PT-2024-13139 · Delta Electronics · Dopsoft

·

CVE-2023-43817

·

Published

2024-01-18

·

Updated

2024-01-20

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics Delta Industrial Automation DOPSoft version 2
Description A buffer overflow exists when parsing the wMailContentLen field of a DPS file. An anonymous attacker can exploit this issue by enticing a user to open a specially crafted DPS file, potentially achieving code execution.
Recommendations For Delta Electronics Delta Industrial Automation DOPSoft version 2, consider avoiding the use of DPS files from untrusted sources until a patch is available. As a temporary workaround, restrict the ability to open DPS files to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-43817

Affected Products

Dopsoft