First published: Mon Jan 11 2021(Updated: )
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Cncsoft-b | <=1.0.0.2 | |
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27287 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation CNCSoft-B.
To exploit this vulnerability, the target must visit a malicious page or open a malicious file.
The severity of CVE-2020-27287 is high with a CVSS score of 7.8.
The vulnerability affects Delta Industrial Automation CNCSoft-B version 1.0.0.2.
Delta Industrial Automation has not released a patch for this vulnerability at the moment. It is recommended to avoid visiting untrusted websites or opening suspicious files.