Show filters
232 Total Results
Displaying 1-10 of 232
Sort by:
Attacker Value
High
CVE-2023-1133
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.
3
Attacker Value
Low
CVE-2021-38406
Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.
3
Attacker Value
Unknown
CVE-2024-47131
Disclosure Date: November 11, 2024 (last updated January 31, 2025)
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetObjectInfo can be exploited, allowing the attacker to remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-39605
Disclosure Date: November 11, 2024 (last updated January 31, 2025)
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetParameter can be exploited, allowing the attacker to remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-39354
Disclosure Date: November 11, 2024 (last updated January 31, 2025)
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in CEtherIPTagItem can be exploited, allowing the attacker to remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-47966
Disclosure Date: October 10, 2024 (last updated October 18, 2024)
Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-47965
Disclosure Date: October 10, 2024 (last updated October 18, 2024)
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-47964
Disclosure Date: October 10, 2024 (last updated October 18, 2024)
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-47963
Disclosure Date: October 10, 2024 (last updated October 18, 2024)
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-47962
Disclosure Date: October 10, 2024 (last updated October 18, 2024)
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.
0