ZDI-CAN-23084: ZDI-24-632: Delta Electronics CNCSoft-G2 DOPSoft DPAX File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-G2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-4192.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23084?
The severity of ZDI-CAN-23084 is critical due to its potential for remote code execution.
How do I fix ZDI-CAN-23084?
To fix ZDI-CAN-23084, update CNCSoft-G2 to the latest software version provided by Delta Electronics.
What type of attacks does ZDI-CAN-23084 facilitate?
ZDI-CAN-23084 allows remote attackers to execute arbitrary code on affected installations.
Is user interaction required to exploit ZDI-CAN-23084?
Yes, user interaction is required, such as visiting a malicious page or opening a malicious file.
Which software is affected by ZDI-CAN-23084?
ZDI-CAN-23084 affects Delta Electronics CNCSoft-G2 installations.