First published: Mon Jan 11 2021(Updated: )
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Cncsoft-b | <=1.0.0.2 | |
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27289 is a vulnerability in Delta Industrial Automation CNCSoft-B that allows remote attackers to execute arbitrary code.
CVE-2020-27289 has a severity rating of 7.8 out of 10, which is classified as high.
The specific flaw in CVE-2020-27289 exists within the DOPSoft DPA file parsing, allowing untrusted pointer dereference and remote code execution.
Delta Industrial Automation CNCSoft-B versions up to and including 1.0.0.2 are affected by CVE-2020-27289.
CVE-2020-27289 requires user interaction, such as visiting a malicious page or opening a malicious file, to be exploited.