CVE-2024-12858: Delta Electronics CNCSoft-G2 Heap-based Buffer Overflow
Published Mar 13, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate of CVE-2025-22880
Affected Software
4 affected components
Delta Electronics CNCSoft-G2<2.1.0.16
: Delta Electronics CNCSoft-G2: Version 2.0.0.5 (CVE-2024-39880, CVE-2024-39881, CVE-2024-39882, CVE-2024-39883)
: Delta Electronics CNCSoft-G2: Version 2.1.0.10 and prior (CVE-2025-22880)
: Delta Electronics CNCSoft-G2: Version 2.1.0.16 and prior (CVE-2024-12858)
Remediation
Information
Delta Electronics recommends users update to CNCSoft-G2 V2.1.0.10 https://downloadcenter.deltaww.com/en-US/DownloadCenter or later.
Delta has published Delta-PCSA-2025-00002 https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2025-00002_CNCSoft-G2%20-%20Heap-based%20Buffer%20Overflow_v2.pdf in both English and Chinese on their security website to provide more details about these issues.
Event History
Mar 13, 2025
CVE Published
via MITRE·04:47 PM
Rejected
via MITRE·04:47 PM
Data Sourced
via NVD·05:15 PM
Description
Apr 2, 2025
Rejected
via MITRE·03:02 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-12858?
CVE-2024-12858 is considered a high-severity vulnerability due to its exploitation potential in heap-based buffer overflow scenarios.
2
How do I fix CVE-2024-12858?
To mitigate CVE-2024-12858, update Delta Electronics CNCSoft-G2 to version 2.1.0.17 or later.
3
What types of attacks can CVE-2024-12858 enable?
CVE-2024-12858 can allow attackers to execute arbitrary code on a vulnerable system through crafted user input.
4
Which versions of CNCSoft-G2 are affected by CVE-2024-12858?
CVE-2024-12858 affects Delta Electronics CNCSoft-G2 versions 2.1.0.16 and prior.
5
How can I identify if my system is vulnerable to CVE-2024-12858?
You can verify your system's version of CNCSoft-G2 against the affected versions listed for CVE-2024-12858.