PT-2023-1547 · Delta Electronics · Dopsoft

CVE-2023-0123

·

Publicado

2023-02-02

·

Atualizado

2023-08-31

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics DOPSoft versions 4.00.16.22 and prior
Description The issue is caused by a stack-based buffer overflow. This could allow an attacker to execute arbitrary code remotely when a specially crafted file is introduced to the software. The exploitation occurs through a malformed file, which can lead to remote code execution.
Recommendations For versions 4.00.16.22 and prior, update to a version that fixes the stack-based buffer overflow issue to prevent remote code execution. As a temporary workaround, consider restricting the introduction of external files to the software until a patch is available.

Correção

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-00998
CVE-2023-0123
ZDI-23-1288
ZDI-23-1289
ZDI-23-1290
ZDI-23-1292
ZDI-23-1293

Produtos afetados

Dopsoft