Out-of-bounds read in Delta Industrial Automation DOPSoft - CVE-2019-13513

 

Out-of-bounds read in Delta Industrial Automation DOPSoft - CVE-2019-13513

Published: August 21, 2019


Vulnerability identifier: #VU20350
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13513
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition when processing a specially crafted project file. A local attacker can create a specially crafted project file, trigger out-of-bounds read error and read contents of memory on the system and cause it to crash.


Affected software

Delta Industrial Automation DOPSoft
Amazon Linux AMI
Gentoo Linux
Opensuse

How to mitigate CVE-2019-13513

Install updates from vendor's website.

Delta Industrial Automation DOPSoft - update to 4.00.06.47

External References

Related Security Bulletins