First published: Thu Feb 29 2024(Updated: )
Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Delta Electronics CNCSoft-B DOPSoft | ||
Delta Industrial Automation CNCSoft-B | <=1.0.0.4 | |
Delta Electronics DOPSoft | <4.0.0.94 |
Delta recommends users upgrade to CNCSoft-B v1.0.0.4 https://downloadcenter.deltaww.com/en-US/DownloadCenter , which includes DOPSoft v4.0.0.94.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1595 is considered a high severity vulnerability due to its potential for DLL hijacking and full system compromise.
To fix CVE-2024-1595, upgrade Delta Electronics CNCSoft-B DOPSoft to version v4.0.0.82 or later.
CVE-2024-1595 allows attackers to exploit insecure library loading to execute malicious code, potentially taking control of the system.
Versions of Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 are affected by CVE-2024-1595.
Yes, CVE-2024-1595 can be exploited remotely if an attacker has access to the network where the vulnerable software is installed.