#VU29432 Out-of-bounds read in Delta Industrial Automation DOPSoft
Published: July 1, 2020
Delta Industrial Automation DOPSoft
Delta Electronics, Inc.
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when parsing the EnRcpNoName information within DPA files. A remote attacker can create a specially crafted DPA file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.
Remediation
External links
- https://www.zerodayinitiative.com/advisories/ZDI-20-799/
- https://www.zerodayinitiative.com/advisories/ZDI-20-798/
- https://www.zerodayinitiative.com/advisories/ZDI-20-797/
- https://www.zerodayinitiative.com/advisories/ZDI-20-796/
- https://www.zerodayinitiative.com/advisories/ZDI-20-795/
- https://www.zerodayinitiative.com/advisories/ZDI-20-794/
- https://www.zerodayinitiative.com/advisories/ZDI-20-793/
- https://www.zerodayinitiative.com/advisories/ZDI-20-792/
- https://www.zerodayinitiative.com/advisories/ZDI-20-791/
- https://www.zerodayinitiative.com/advisories/ZDI-20-790/
- https://www.zerodayinitiative.com/advisories/ZDI-20-788/
- https://www.zerodayinitiative.com/advisories/ZDI-20-787/
- https://www.us-cert.gov/ics/advisories/icsa-20-182-01