PT-2024-32912 · Delta Electronics · Cncsoft-G2

Bobby Gould

+2

·

Published

2024-10-10

·

Updated

2024-10-17

·

CVE-2024-47962

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Delta Electronics CNCSoft-G2 version 2.1.0.10
Description The issue is related to a lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. This allows an attacker to manipulate an insider to visit a malicious page or file, potentially leading to the execution of code in the context of the current process. The vulnerability poses a serious cybersecurity threat due to the possibility of remote code execution.
Recommendations For Delta Electronics CNCSoft-G2 version 2.1.0.10, upgrade immediately to mitigate the risk of system compromise on affected devices. As a temporary workaround, consider restricting access to potentially vulnerable file parsing functions until a patch is available. Avoid using the software to parse untrusted files, such as ALM, DPAX, or CMT files, until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47962
ZDI-24-1389
ZDI-24-1390
ZDI-24-1395
ZDI-24-1396
ZDI-24-1397
ZDI-24-1398
ZDI-24-1401
ZDI-24-1402
ZDI-24-1404
ZDI-24-1405
ZDI-24-1406
ZDI-24-1407
ZDI-24-1410

Affected Products

Cncsoft-G2