Use After Free Vulnerability in ISPSoft by Delta Electronics
CVE-2020-27280

7.8HIGH

Key Information:

Vendor

Deltaww

Status
Vendor
CVE Published:
26 January 2021

What is CVE-2020-27280?

A use after free issue has been identified in ISPSoft, affecting versions 3.12 and prior. This vulnerability arises from improper handling of project files, which allows an attacker to create a specially crafted project file that can lead to arbitrary code execution on the affected system. When exploited, this vulnerability could enable unauthorized control over the system, posing serious security risks to users.

Affected Version(s)

ISPSoft v3.12 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.