Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buffer where the position can be determined by a value read from a .dpa file. This may cause improper restriction of operations within the bounds of the memory buffer, allow remote code execution, alter the intended control flow, allow reading of sensitive information, or cause the application to crash.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-151-01 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/104375 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-06-18 12:29
Updated : 2019-10-09 16:32
NVD link : CVE-2018-10623
Mitre link : CVE-2018-10623
JSON object : View
CWE
CWE-125
Out-of-bounds Read
Products Affected
deltaww
- delta_industrial_automation_dopsoft