In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may trigger multiple out-of-bounds read vulnerabilities, which may allow information disclosure, remote code execution, or crash of the application.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.us-cert.gov/ics/advisories/icsa-19-225-01 | us government resource third party advisory mitigation |
https://www.zerodayinitiative.com/advisories/ZDI-19-720/ | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-19-722/ | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-19-719/ | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-19-718/ | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-19-721/ | vdb entry third party advisory |