CVE-2017-16745
An access of resource using incompatible type ('type confusion') vulnerability may allow an attacker to execute remote code when processing specially crafted .dpb files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. An access of resource using incompatible type ('type confusion') vulnerability may allow an attacker to execute remote code when processing specially crafted .dpb files.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-843, CWE-704
- Affected
- deltaww/delta industrial automation screen editor
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/102426Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-004-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102426Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-004-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.