CVE-2022-4634

All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-01 Patch Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:deltaww:cncsoft:*:*:*:*:*:*:*:*
cpe:2.3:a:deltaww:screeneditor:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:58

Type Values Removed Values Added
Summary All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code. All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.

10 Feb 2023, 01:07

Type Values Removed Values Added
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-01 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-01 - Patch, Third Party Advisory, US Government Resource
CPE cpe:2.3:a:deltaww:cncsoft:*:*:*:*:*:*:*:*
cpe:2.3:a:deltaww:screeneditor:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Deltaww
Deltaww cncsoft
Deltaww screeneditor
CWE CWE-121 CWE-787

03 Feb 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-03 03:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-4634

Mitre link : CVE-2022-4634

CVE.ORG link : CVE-2022-4634


JSON object : View

Products Affected

deltaww

  • cncsoft
  • screeneditor
CWE
CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow