ZDI-CAN-24197: ZDI-24-1408: Delta Electronics CNCSoft-G2 DPAX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-G2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-47963.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24197?
ZDI-CAN-24197 is categorized as a critical vulnerability due to its potential for unauthorized remote code execution.
How do I fix ZDI-CAN-24197?
The recommended fix for ZDI-CAN-24197 is to update to the latest version of Delta Electronics CNCSoft-G2 where the vulnerability has been patched.
What are the consequences of ZDI-CAN-24197 exploitation?
Exploitation of ZDI-CAN-24197 can allow remote attackers to execute arbitrary code, potentially leading to full system compromise.
Does ZDI-CAN-24197 require user interaction to be exploited?
Yes, ZDI-CAN-24197 requires user interaction, as the target must visit a malicious webpage or open a malicious file.
Which software is affected by ZDI-CAN-24197?
ZDI-CAN-24197 affects Delta Electronics CNCSoft-G2 installations.