First published: Mon May 10 2021(Updated: )
Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Cncsoft Screeneditor | <1.01.30 | |
Delta Industrial Automation CNCSoft ScreenEditor | ||
Delta Electronics CNCSoft ScreenEditor versions prior to v1.01.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-22672.
The severity level of CVE-2021-22672 is high.
Delta Industrial Automation CNCSoft ScreenEditor versions up to and excluding 1.01.30 are affected by CVE-2021-22672.
CVE-2021-22672 can be exploited by remote attackers executing arbitrary code on affected installations of Delta Industrial Automation CNCSoft ScreenEditor through user interaction with a malicious page or file.
Yes, you can find references for CVE-2021-22672 at the following links: - [US-CERT Advisory](https://us-cert.cisa.gov/ics/advisories/icsa-21-124-02) - [Zero Day Initiative Advisory](https://www.zerodayinitiative.com/advisories/ZDI-21-524/)