Lucene search

K
cvelistIcscertCVELIST:CVE-2023-5068
HistorySep 21, 2023 - 10:01 p.m.

CVE-2023-5068 Delta Electronics DIAScreen Out-of-bounds Write

2023-09-2122:01:07
CWE-787
icscert
www.cve.org
3
delta electronics
diascreen
out-of-bounds write
vulnerability
cve-2023-5068
parsing
input file
attacker
code execution

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.099

Percentile

94.9%

Delta Electronics DIAScreen may write past the end of an allocated
buffer while parsing a specially crafted input file. This could allow an
attacker to execute code in the context of the current process.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "DIAScreen",
    "vendor": "Delta Electronics",
    "versions": [
      {
        "lessThan": "v1.3.2",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.099

Percentile

94.9%

Related for CVELIST:CVE-2023-5068