Vulnerability CVE-2018-17927


Published: 2018-10-11   Modified: 2018-10-12

Description:
In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution.

Type:

CWE-787

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Deltaww -> Tpeditor 

 References:
http://www.securityfocus.com/bid/105682
https://ics-cert.us-cert.gov/advisories/ICSA-18-284-03

Copyright 2024, cxsecurity.com

 

Back to Top