PT-2019-13379 · Delta Industrial Automation · Dopsoft

·

CVE-2019-13513

·

Publicado

2019-08-15

·

Atualizado

2023-03-03

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Industrial Automation DOPSoft versions 4.00.06.15 and prior
Description The issue arises when processing a specially crafted project file, which may trigger multiple out-of-bounds read vulnerabilities. This could lead to information disclosure, remote code execution, or cause the application to crash.
Recommendations For versions 4.00.06.15 and prior, avoid processing untrusted or specially crafted project files until a fix is available. As a temporary workaround, consider restricting access to project file parsing functionality to minimize the risk of exploitation.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13513
ZDI-19-718
ZDI-19-719
ZDI-19-720
ZDI-19-721
ZDI-19-722

Produtos afetados

Dopsoft