First published: Wed Apr 17 2019(Updated: )
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Cncsoft Screeneditor | <=1.00.88 | |
Delta Industrial Automation CNCSoft ScreenEditor |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10951 is a vulnerability that allows remote attackers to execute arbitrary code on vulnerable installations of Delta Industrial Automation CNCSoft ScreenEditor.
To exploit this vulnerability, the target must visit a malicious page or open a malicious file requiring user interaction.
The affected software is Delta Industrial Automation CNCSoft ScreenEditor version 1.00.88.
The severity of CVE-2019-10951 is high with a CVSS score of 7.8.
To fix CVE-2019-10951, users are advised to apply the necessary security patches or updates provided by Delta Industrial Automation.