First published: Tue Jan 26 2021(Updated: )
TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Delta Industrial Automation TPEditor | <=1.98 | |
Delta Electronics (Delta) TPEditor: v1.98 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27284 is a vulnerability found in TPEditor (v1.98 and prior), which allows an attacker to execute arbitrary code by crafting a special project file.
CVE-2020-27284 affects TPEditor (v1.98 and prior) and allows an attacker to exploit two out-of-bounds write instances in the way it processes project files.
CVE-2020-27284 has a severity rating of 7.8, which is considered high.
An attacker can exploit CVE-2020-27284 by crafting a special project file that triggers the out-of-bounds write instances in TPEditor, allowing for arbitrary code execution.
At the moment, there is no specific fix available for CVE-2020-27284. It is recommended to update to a version of TPEditor that is not vulnerable.