First published: Thu Mar 13 2025(Updated: )
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. *** Duplicate of CVE-2025-22880 ***
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Delta Electronics CNCSoft-G2 | <2.1.0.16 | |
Delta Electronics CNCSoft-G2 | ||
Delta Electronics CNCSoft-G2 | ||
Delta Electronics CNCSoft-G2 |
Delta Electronics recommends users update to CNCSoft-G2 V2.1.0.10 https://downloadcenter.deltaww.com/en-US/DownloadCenter or later. Delta has published Delta-PCSA-2025-00002 https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2025-00002_CNCSoft-G2%20-%20Heap-based%20Buffer%20Overflow_v2.pdf in both English and Chinese on their security website to provide more details about these issues.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12858 is considered a high-severity vulnerability due to its exploitation potential in heap-based buffer overflow scenarios.
To mitigate CVE-2024-12858, update Delta Electronics CNCSoft-G2 to version 2.1.0.17 or later.
CVE-2024-12858 can allow attackers to execute arbitrary code on a vulnerable system through crafted user input.
CVE-2024-12858 affects Delta Electronics CNCSoft-G2 versions 2.1.0.16 and prior.
You can verify your system's version of CNCSoft-G2 against the affected versions listed for CVE-2024-12858.