First published: Mon Jan 11 2021(Updated: )
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Cncsoft-b | <=1.0.0.2 | |
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-27293 is high with a score of 7.8.
CVE-2020-27293 allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation CNCSoft-B by exploiting a type confusion vulnerability and tricking the user into visiting a malicious page or opening a malicious file.
CVE-2020-27293 affects Delta Industrial Automation CNCSoft-B version 1.0.0.2.
The CWE ID for CVE-2020-27293 is 843.
You can find more information about CVE-2020-27293 at the following references: [1](https://us-cert.cisa.gov/ics/advisories/icsa-21-007-04) and [2](https://www.zerodayinitiative.com/advisories/ZDI-21-045/).