CVE-2023-5068: Delta Electronics DIAScreen Out-of-bounds Write
Published Sep 21, 2023
·Updated
Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file. This could allow an attacker to execute code in the context of the current process.
Affected Software
1 affected component
Deltaww Diascreen<1.3.2
Remediation
Information
Delta Electronics has released a new version (v1.3.2) of DIAScreen to address this issue.
Users can download it at the download center of DIAStudio. https://diastudio.deltaww.com/home/downloads (Login required)
Event History
Sep 21, 2023
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-5068.
2
What is the severity level of CVE-2023-5068?
The severity level of CVE-2023-5068 is high.
3
How does this vulnerability impact Delta Electronics DIAScreen?
This vulnerability allows an attacker to execute code in the context of the current process of Delta Electronics DIAScreen.
4
Which versions of Delta Electronics DIAScreen are affected by CVE-2023-5068?
Versions up to and exclusive of 1.3.2 of Delta Electronics DIAScreen are affected by CVE-2023-5068.
5
How can I fix the vulnerability in Delta Electronics DIAScreen?
To fix the vulnerability in Delta Electronics DIAScreen, update to a version beyond 1.3.2.