Stack-Based Buffer Overflow Vulnerabilities in Delta Industrial Automation TPEditor
CVE-2018-17929

7.8HIGH

Key Information:

Vendor
CVE Published:
11 October 2018

Summary

Delta Industrial Automation's TPEditor software is vulnerable to multiple stack-based buffer overflow issues in versions up to 1.90. These vulnerabilities can be exploited by an attacker through specially crafted project files that lack adequate user input validation. When processing these files, the stack may be manipulated, potentially allowing remote execution of arbitrary code. Organizations using vulnerable versions of TPEditor need to ensure proper validation mechanisms are in place and should consider upgrading to avoid exploitation risks.

Affected Version(s)

Delta Industrial Automation TPEditor TPEditor Versions 1.90 and prior.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.