CVE-2016-5805
There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of arbitrary code or a denial of service.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of arbitrary code or a denial of service.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- delta electronics/ispsoft · delta electronics/pmsoft · delta electronics/wplsoft
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/94887Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-348-03Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/94887Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-348-03Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.