ZDI-24-626: Delta Electronics CNCSoft-G2 DOPSoft DPAX File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-G2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-4192.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-626?
The severity of ZDI-24-626 is classified as critical due to its potential for remote code execution.
How do I fix ZDI-24-626?
To fix ZDI-24-626, apply the latest security patches provided by Delta Electronics for the CNCSoft-G2 software.
What type of attack can exploit ZDI-24-626?
ZDI-24-626 can be exploited through remote code execution, requiring user interaction to open a malicious file or visit a malicious page.
Who is affected by ZDI-24-626?
Organizations using Delta Electronics CNCSoft-G2 software are affected by vulnerability ZDI-24-626.
Is user interaction required for ZDI-24-626 exploitation?
Yes, user interaction is required to exploit ZDI-24-626 by having the user visit a malicious site or open a harmful file.