Description
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Problem types
CWE-121 Stack-based Buffer Overflow
Product status
Any version before 2.1.0.34
Credits
Jessie Cooper of CISA
References
filecenter.deltaww.com/... Buffer Overflow Vulnerability.pdf