CVE-2018-7494
WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.78% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-119
- Affected
- deltaww/wplsoft
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/103179Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-058-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/103179Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-058-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.