First published: Tue Jan 26 2021(Updated: )
A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Ispsoft | <=3.12 | |
Delta Electronics CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing | ||
Delta Electronics | ||
Delta Electronics |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27280 has been classified with a high severity due to its potential for arbitrary code execution.
To mitigate CVE-2020-27280, users should upgrade to ISPSoft version 3.13 or later.
CVE-2020-27280 allows an attacker to craft project files that may execute arbitrary code on the affected system.
ISPSoft versions up to and including 3.12 are vulnerable to CVE-2020-27280.
The vendor of the affected software is Delta Electronics.