Delta Electronics WPLSoft Buffer-Overflow
CVE-2023-5130
8.2HIGH
Summary
A buffer overflow vulnerability has been identified in the WPLSoft software by Delta Electronics, which facilitates programming and managing Delta's PLCs. An anonymous attacker could exploit this flaw by persuading a user to open a maliciously crafted DVP file. If successful, this exploitation could allow the attacker to execute arbitrary code on the user’s system, potentially leading to unauthorized access and control over the affected device. Users are advised to implement mitigation strategies and stay updated with security patches from Delta Electronics to safeguard against possible exploits.
Affected Version(s)
WPLSoft 2.42.11
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Exodus Intelligence