ZDI-23-1400: Delta Electronics CNCSoft-B DPA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-B. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-4685.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1400?
The severity of ZDI-23-1400 is high due to the potential for remote code execution.
How do I fix ZDI-23-1400?
To fix ZDI-23-1400, apply the latest security patches provided by Delta Electronics for CNCSoft-B.
Who is affected by ZDI-23-1400?
Any user or organization using Delta Electronics CNCSoft-B is affected by ZDI-23-1400.
What types of attacks does ZDI-23-1400 enable?
ZDI-23-1400 enables remote code execution attacks requiring user interaction through a malicious page or file.
Is user interaction needed to exploit ZDI-23-1400?
Yes, user interaction is required for exploiting ZDI-23-1400 as the target must visit a malicious site or open a malicious file.