IM
IronMonkey Threat Research

CVE-2018-7494 HIGH

Published: 2018-05-04 | Last Modified: 2026-06-17 | Status: Modified

Description

WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

Additional Descriptions (1)

WPLSoft en Delta Electronics en versiones 2.45.0 y anteriores emplea un búfer de pila con un tamaño fijo en el que un valor más grande que el búfer puede ser leído en en el búfer desde un archivo. Esto provoca que el búfer se sobrescriba, lo que podría permitir la ejecución remota de código o que la aplicación se cierre inesperadamente.

CVSS Metrics

Base Score: 6.8 (MEDIUM)

AV:N/AC:M/Au:N/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-121
[email protected] Primary
en CWE-119

Affected Products

Vendor Product Version Update Type
deltaww wplsoft * <built-in method update of dict object at 0x7e60bae0dec0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:deltaww:wplsoft:*:*:*:*:*:*:*:*

References

Notification
Message here