First published: Mon Jan 11 2021(Updated: )
A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Delta Industrial Automation CNCSoft ScreenEditor | ||
Deltaww Cncsoft Screeneditor | <=1.01.26 | |
Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-27281.
The affected software is Delta Industrial Automation CNCSoft ScreenEditor version up to 1.01.26.
CVE-2020-27281 has a severity rating of 7.8 (high).
Remote attackers can exploit CVE-2020-27281 by tricking the target into visiting a malicious page or opening a malicious file.
Yes, you can find more information about CVE-2020-27281 at the following references: [US-CERT Advisory](https://us-cert.cisa.gov/ics/advisories/icsa-21-005-06) and [ZeroDay Initiative Advisory](https://www.zerodayinitiative.com/advisories/ZDI-21-039/).