CVE-2018-10594: Buffer Overflow
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM5x0, AHSIM5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10594?
CVE-2018-10594 is rated as a high-severity vulnerability due to its potential to lead to buffer overflow attacks.
How do I fix CVE-2018-10594?
To mitigate CVE-2018-10594, upgrade Delta Industrial Automation COMMGR to version 1.09 or later.
What are the affected versions of Delta COMMGR in CVE-2018-10594?
CVE-2018-10594 affects Delta COMMGR versions up to and including 1.08.
Which products are vulnerable along with Delta COMMGR in CVE-2018-10594?
CVE-2018-10594 affects Delta COMMGR and does not impact the PLC Simulators listed in the provided information.
What type of attacks can result from CVE-2018-10594?
CVE-2018-10594 can allow an attacker to execute arbitrary code due to improper verification of network packet lengths.