CVE-2021-38404: Delta Electronics DOPSoft 2 Heap-based Buffer Overflow
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Since Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) is end-of-life and will not receive updates to mitigate these vulnerabilities, switch to the replacement software when available.
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38404.
What is the severity of CVE-2021-38404?
The severity of CVE-2021-38404 is high with a CVSS score of 7.8.
What is the affected software?
The affected software is Delta Electronic DOPSoft 2 (Version 2.00.07 and prior).
What is the impact of CVE-2021-38404?
The vulnerability could result in a heap-based buffer overflow, allowing an attacker to execute code in the context of the current process.
Is there a fix available for CVE-2021-38404?
Please refer to the vendor's website or security advisories for information on available fixes or patches.