Use-after-free in Delta Industrial Automation DOPSoft - CVE-2019-13514

 

Use-after-free in Delta Industrial Automation DOPSoft - CVE-2019-13514

Published: August 21, 2019


Vulnerability identifier: #VU20351
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13514
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing a specially crafted project file. A local attacker can send a specially crafted project file, trigger a use-after-free vulnerability, gain sensitive information on the target system, execute arbitrary code, or crash the application.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Delta Industrial Automation DOPSoft
Amazon Linux AMI
Gentoo Linux
Opensuse

How to mitigate CVE-2019-13514

Install updates from vendor's website.

Delta Industrial Automation DOPSoft - update to 4.00.06.47

External References

Related Security Bulletins