ZDI-23-808: Delta Electronics CNCSoft-B DOPSoft DPA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published Jun 1, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-B. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Delta Electronics CNCSoft-B
Event History
Jun 1, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-808?
The severity of ZDI-23-808 is high, allowing remote code execution on affected installations.
2
How can I mitigate ZDI-23-808?
To mitigate ZDI-23-808, ensure that users do not interact with suspicious pages or files that could be malicious.
3
What conditions must be met to exploit ZDI-23-808?
Exploitation of ZDI-23-808 requires user interaction with a malicious page or file.
4
Which software is affected by ZDI-23-808?
ZDI-23-808 affects Delta Electronics CNCSoft-B installations.
5
Is user interaction necessary for ZDI-23-808 exploitation?
Yes, user interaction is necessary for the exploitation of ZDI-23-808.