Lucene search

K
cvelistIcscertCVELIST:CVE-2023-0124
HistoryFeb 02, 2023 - 10:59 p.m.

CVE-2023-0124 CVE-2023-0124

2023-02-0222:59:15
CWE-787
icscert
www.cve.org
3
delta electronics
dopsoft
vulnerable
out-of-bounds write
remote code execution

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

28.8%

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "DOPSoft",
    "vendor": "Delta Industrial Automation",
    "versions": [
      {
        "lessThanOrEqual": "4.00.16.22",
        "status": "affected",
        "version": "all versions",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

28.8%

Related for CVELIST:CVE-2023-0124