Delta Electronics WPLSoft Buffer-Overflow
CVE-2023-5130

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
18 January 2024

Summary

A buffer overflow vulnerability has been identified in the WPLSoft software by Delta Electronics, which facilitates programming and managing Delta's PLCs. An anonymous attacker could exploit this flaw by persuading a user to open a maliciously crafted DVP file. If successful, this exploitation could allow the attacker to execute arbitrary code on the user’s system, potentially leading to unauthorized access and control over the affected device. Users are advised to implement mitigation strategies and stay updated with security patches from Delta Electronics to safeguard against possible exploits.

Affected Version(s)

WPLSoft 2.42.11

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Exodus Intelligence
.