Delta Electronics Delta Industrial Automation DOPSoft DPS File wLogTitlesPrevValueLen Buffer Overflow Remote Code Execution
CVE-2023-43820

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
18 January 2024

Summary

A stack-based buffer overflow vulnerability exists in Delta Electronics' Delta Industrial Automation DOPSoft application when processing the wLogTitlesPrevValueLen field within a DPS file. An unauthenticated attacker could exploit this flaw by tricking a user into opening a specially crafted DPS file. Successful exploitation may lead to the execution of arbitrary code on the affected system, potentially compromising sensitive data and allowing unauthorized control over the system.

Affected Version(s)

DOPSoft 2.00.00.00 <= 2.00.07.04

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Exodus Intelligence
.