Lucene search

K
cvelistIcscertCVELIST:CVE-2021-38404
HistorySep 17, 2021 - 6:54 p.m.

CVE-2021-38404 Delta Electronics DOPSoft 2 Heap-based Buffer Overflow

2021-09-1718:54:45
CWE-122
icscert
www.cve.org
7
delta electronics
dopsoft 2
version 2.00.07
heap-based buffer overflow
validation
user-supplied data
parsing
project files
vulnerability
code execution

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.014

Percentile

86.8%

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

CNA Affected

[
  {
    "product": "DOPSoft 2",
    "vendor": "Delta Electronics",
    "versions": [
      {
        "lessThanOrEqual": "2.00.07",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.014

Percentile

86.8%

Related for CVELIST:CVE-2021-38404