CVE-2020-27280: Use After Free
Published Jan 26, 2021
·Updated
A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.
Affected Software
4 affected components
Delta Electronics (Delta) CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing
Delta Electronics (Delta) COUNTRIES/AREAS DEPLOYED: Worldwide
Delta Electronics (Delta) COMPANY HEADQUARTERS LOCATION: Taiwan
Deltaww Ispsoft<=3.12
Event History
Jan 26, 2021
CVE Published
via MITRE·12:51 PM
Data Sourced
via MITRE·12:51 PM
DescriptionWeakness
Aug 4, 2024
Data Sourced
via ICS·04:18 PM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-27280?
CVE-2020-27280 has been classified with a high severity due to its potential for arbitrary code execution.
2
How do I fix CVE-2020-27280?
To mitigate CVE-2020-27280, users should upgrade to ISPSoft version 3.13 or later.
3
What is the impact of CVE-2020-27280?
CVE-2020-27280 allows an attacker to craft project files that may execute arbitrary code on the affected system.
4
Which versions of ISPSoft are affected by CVE-2020-27280?
ISPSoft versions up to and including 3.12 are vulnerable to CVE-2020-27280.
5
Who is the vendor of the software affected by CVE-2020-27280?
The vendor of the affected software is Delta Electronics.