First published: Fri Sep 08 2023(Updated: )
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-B. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-4685.
Affected Software | Affected Version | How to fix |
---|---|---|
CNCSoft by Delta Electronics |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-23-1400 is high due to the potential for remote code execution.
To fix ZDI-23-1400, apply the latest security patches provided by Delta Electronics for CNCSoft-B.
Any user or organization using Delta Electronics CNCSoft-B is affected by ZDI-23-1400.
ZDI-23-1400 enables remote code execution attacks requiring user interaction through a malicious page or file.
Yes, user interaction is required for exploiting ZDI-23-1400 as the target must visit a malicious site or open a malicious file.