First published: Tue Feb 27 2018(Updated: )
WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Wplsoft | <=2.45.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7494 is a vulnerability in WPLSoft in Delta Electronics versions 2.45.0 and prior that allows for remote code execution or application crashes.
The severity of CVE-2018-7494 is high with a CVSS score of 8.8.
CVE-2018-7494 affects WPLSoft in Delta Electronics versions 2.45.0 and prior, allowing a buffer overflow and potential remote code execution or application crashes.
Yes, upgrading to a version later than 2.45.0 of WPLSoft in Delta Electronics will fix the vulnerability.
More information about CVE-2018-7494 can be found at the following references: [http://www.securityfocus.com/bid/103179](http://www.securityfocus.com/bid/103179) and [https://ics-cert.us-cert.gov/advisories/ICSA-18-058-02](https://ics-cert.us-cert.gov/advisories/ICSA-18-058-02).