Use-after-free in Delta Industrial Automation DOPSoft - CVE-2019-13514

 

Use-after-free in Delta Industrial Automation DOPSoft - CVE-2019-13514

Published: August 21, 2019


Vulnerability identifier: #VU20351
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-13514
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Delta Electronics, Inc.
Affected software:
Delta Industrial Automation DOPSoft

Detailed vulnerability description

The vulnerability allows a local attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing a specially crafted project file. A local attacker can send a specially crafted project file, trigger a use-after-free vulnerability, gain sensitive information on the target system, execute arbitrary code, or crash the application.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


How to mitigate CVE-2019-13514

Install updates from vendor's website.

Sources