PT-2024-28706 · Delta Electronics · Cncsoft-G2

Bobby Gould

+2

·

Published

2024-07-09

·

Updated

2024-08-29

·

CVE-2024-39880

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics CNCSoft-G2 (affected versions not specified)
Description The issue is related to a lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. This can be exploited if a target visits a malicious page or opens a malicious file, allowing an attacker to execute code in the context of the current process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-39880
ZDI-24-917
ZDI-24-918
ZDI-24-919
ZDI-24-920
ZDI-24-921
ZDI-24-922
ZDI-24-923
ZDI-24-924
ZDI-24-925
ZDI-24-926
ZDI-24-927
ZDI-24-928
ZDI-24-929
ZDI-24-930
ZDI-24-931
ZDI-24-932
ZDI-24-933
ZDI-24-934
ZDI-24-935
ZDI-24-936
ZDI-24-937
ZDI-24-938
ZDI-24-939
ZDI-24-940
ZDI-24-943
ZDI-24-944

Affected Products

Cncsoft-G2