Lucene search

K
cvelistIcscertCVELIST:CVE-2024-1595
HistoryFeb 29, 2024 - 7:16 p.m.

CVE-2024-1595 Delta Electronics CNCSoft-B DOPSoft Uncontrolled Search Path Element

2024-02-2919:16:08
CWE-427
icscert
www.cve.org
3
delta electronics cncsoft-b
dopsoft
v4.0.0.82
insecurely loads libraries
dll hijacking
system takeover

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

28.8%

Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82

insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "CNCSoft-B v1.0.0.4 DOPSoft",
    "vendor": "Delta Electronics",
    "versions": [
      {
        "lessThan": "v4.0.0.82",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

28.8%

Related for CVELIST:CVE-2024-1595