First published: Thu Feb 02 2023(Updated: )
All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Deltaww Cncsoft | <1.01.34 | |
Deltaww Screeneditor | <1.01.5 | |
Delta Electronics CNCSoft | <1.01.34 | 1.01.34 |
Delta Electronics Running ScreenEditor: All versions 1.01.5 and prior |
Delta Electronics released an updated version of CNCSoft and recommends users update to v1.01.34 or later https://downloadcenter.deltaww.com/en-US/DownloadCenter .
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4634 is a vulnerability in Delta Electronic's CNCSoft and ScreenEditor software that allows an attacker to remotely execute arbitrary code.
The severity of CVE-2022-4634 is high, with a CVSS score of 7.8.
All versions prior to Delta Electronic's CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are affected by CVE-2022-4634.
An attacker can exploit CVE-2022-4634 by leveraging a stack-based buffer overflow vulnerability in the affected software to execute arbitrary code remotely.
Yes, updating to Delta Electronic's CNCSoft version 1.01.34 and ScreenEditor versions 1.01.5 or later can mitigate the vulnerability.