Null Pointer Dereference in Delta Electronics CNCSoft-B Software
CVE-2020-27289

7.8HIGH

Key Information:

Vendor

Deltaww

Vendor
CVE Published:
11 January 2021

What is CVE-2020-27289?

Delta Electronics CNCSoft-B, particularly Versions 1.0.0.2 and earlier, is susceptible to a null pointer dereference vulnerability. This issue occurs while processing project files, potentially allowing an attacker to exploit the flaw and execute arbitrary code within the application context. Organizations utilizing CNCSoft-B should assess their systems for this vulnerability to mitigate associated risks.

Affected Version(s)

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.