First published: Tue Apr 27 2021(Updated: )
CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Criticalmanufacturing Cncsoft-b | <=1.0.0.3 | |
Delta Industrial Automation CNCSoft-B DOPSoft | ||
Delta Electronics CNCSoft-B Versions 1.0.0.3 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22664 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Delta Industrial Automation CNCSoft-B DOPSoft.
CVE-2021-22664 has a severity score of 7.8 out of 10, indicating a high severity.
Delta Industrial Automation CNCSoft-B DOPSoft installations are affected by CVE-2021-22664.
To exploit CVE-2021-22664, the target must visit a malicious page or open a malicious file.
Yes, you can find more information about CVE-2021-22664 at the following references: [link1](https://us-cert.cisa.gov/ics/advisories/icsa-21-110-05) and [link2](https://www.zerodayinitiative.com/advisories/ZDI-21-444/).