ZDI-24-233: Delta Electronics CNCSoft-B DPA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-B. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-1941.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-233?
The severity of ZDI-24-233 is critical due to its ability to allow remote code execution.
How do I fix ZDI-24-233?
To fix ZDI-24-233, update to the latest version of Delta Electronics CNCSoft-B that addresses this vulnerability.
What types of attacks can exploit ZDI-24-233?
ZDI-24-233 can be exploited through user interaction by visiting a malicious page or opening a malicious file.
Who is affected by ZDI-24-233?
Users and organizations utilizing Delta Electronics CNCSoft-B are affected by ZDI-24-233.
Is user interaction required to exploit ZDI-24-233?
Yes, user interaction is required to exploit ZDI-24-233.