ZDI-CAN-28444: ZDI-26-233: Digilent DASYLab DSA File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Digilent DASYLab. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-0955.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28444?
The severity of ZDI-CAN-28444 is high due to its potential to allow remote code execution.
How do I fix ZDI-CAN-28444?
To fix ZDI-CAN-28444, update to the latest version of Digilent DASYLab that includes the necessary security patches.
What are the potential impacts of ZDI-CAN-28444?
The potential impacts of ZDI-CAN-28444 include unauthorized remote code execution on affected installations.
Is user interaction required to exploit ZDI-CAN-28444?
Yes, user interaction is required to exploit ZDI-CAN-28444 as the target must open a specially crafted DSA file.
Which versions of Digilent DASYLab are affected by ZDI-CAN-28444?
ZDI-CAN-28444 affects all installations of Digilent DASYLab prior to the security updates addressing this vulnerability.