ZDI-24-1468: Delta Electronics DIAScreen DPA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DIAScreen. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-47131.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1468?
The severity of ZDI-24-1468 is critical due to the potential for remote code execution.
How do I fix ZDI-24-1468?
To fix ZDI-24-1468, ensure that you apply the latest security updates provided by Delta Electronics for DIAScreen.
What type of vulnerability is ZDI-24-1468?
ZDI-24-1468 is a remote code execution vulnerability requiring user interaction for exploitation.
Who is affected by ZDI-24-1468?
Users of Delta Electronics DIAScreen software are affected by ZDI-24-1468.
What exploitation method does ZDI-24-1468 involve?
Exploitation of ZDI-24-1468 involves a user visiting a malicious page or opening a malicious file.