First published: Mon Jan 11 2021(Updated: )
Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Dopsoft | <=4.0.8.21 | |
Delta Industrial Automation DOPSoft | ||
Delta Electronics DOPSoft Version 4.0.8.21 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27277 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation DOPSoft.
CVE-2020-27277 has a severity rating of 7.8 (critical).
CVE-2020-27277 affects Delta Industrial Automation DOPSoft versions up to and including 4.0.8.21.
CVE-2020-27277 has two CWE IDs: CWE-476 (NULL Pointer Dereference) and CWE-822 (Untrusted Pointer Dereference).
To fix CVE-2020-27277, it is recommended to update Delta Industrial Automation DOPSoft to a version beyond 4.0.8.21.