ZDI-CAN-23046: ZDI-24-656: Delta Electronics CNCSoft-G2 DOPSoft ALM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-G2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-4192.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23046?
The severity of ZDI-CAN-23046 is critical due to its ability to allow remote code execution.
How do I fix ZDI-CAN-23046?
To fix ZDI-CAN-23046, update your Delta Electronics CNCSoft-G2 software to the latest patched version.
What are the potential consequences of ZDI-CAN-23046?
The potential consequences of ZDI-CAN-23046 include unauthorized access and control over affected systems.
What types of attack vectors are involved in ZDI-CAN-23046?
ZDI-CAN-23046 requires user interaction, specifically visiting a malicious webpage or opening a malicious file.
Is user interaction necessary to exploit ZDI-CAN-23046?
Yes, user interaction is required to exploit ZDI-CAN-23046 through a malicious webpage or file.