Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-124-02 | third party advisory us government resource |
https://www.zerodayinitiative.com/advisories/ZDI-21-524/ | vdb entry third party advisory |