Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 2.1.0.39
affected
Description
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Problem types
Product status
Any version before 2.1.0.39
Credits
Natnael Samson (@NattiSamson) working with TrendAI Zero Day Initiative
Israel Bentley of CISA
References
filecenter.deltaww.com/...le Parsing Out-Of-Bounds Write.pdf