ZDI-24-1469: Delta Electronics DIAScreen DPA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DIAScreen. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-39605.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1469?
ZDI-24-1469 is considered a high-severity vulnerability due to its potential for remote code execution.
How do I fix ZDI-24-1469?
To mitigate ZDI-24-1469, update Delta Electronics DIAScreen to the latest version that addresses this vulnerability.
Who is affected by ZDI-24-1469?
ZDI-24-1469 affects installations of Delta Electronics DIAScreen software that have not been updated with the necessary security patches.
What type of attack vector is associated with ZDI-24-1469?
ZDI-24-1469 can be exploited through a malicious web page or file, requiring user interaction for successful exploitation.
What are the consequences of exploiting ZDI-24-1469?
Exploitation of ZDI-24-1469 could lead to unauthorized remote code execution on the affected system.