ZDI-24-441: Delta Electronics CNCSoft-B DOPSoft Uncontrolled Search Path Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-B. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-1595.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-441?
The severity of ZDI-24-441 is classified as high due to its potential for remote code execution.
How do I fix ZDI-24-441?
To fix ZDI-24-441, update your Delta Electronics CNCSoft-B software to the latest version that includes security patches.
What type of attacks can be performed using ZDI-24-441?
Using ZDI-24-441, attackers can execute arbitrary code by exploiting a vulnerability through user interaction with malicious content.
Is user interaction required to exploit ZDI-24-441?
Yes, user interaction is required for ZDI-24-441, as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-24-441?
ZDI-24-441 affects Delta Electronics CNCSoft-B software installations.