Out-of-Bounds Read Overflow in Delta Industrial Automation CNCSoft ScreenEditor
CVE-2020-6976

5.5MEDIUM

Key Information:

Vendor

Deltaww

Vendor
CVE Published:
18 March 2020

What is CVE-2020-6976?

The CNCSoft ScreenEditor from Delta Industrial Automation is susceptible to an out-of-bounds read overflow vulnerability. This issue arises when a user opens a malicious input file, which lacks proper input validation. Exploiting this vulnerability may allow an attacker to read memory locations outside the intended buffer, potentially leading to sensitive information disclosure.

Affected Version(s)

Delta Industrial Automation CNCSoft ScreenEditor CNCSoft ScreenEditor v1.00.96 and prior

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.