CVE-2016-5802
Delta Industrial Automation PMSoft File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to 2.10.10. Multiple instances of out-of-bounds write conditions may allow malicious files to be read and executed by the affected software.
Ha sido descubierto un problema en Delta Electronics WPLSoft, versiones anteriores a V2.42.11, ISPSoft, versiones anteriores a 3.02.11 y PMSoft, versiones anteriores a 2.10.10. Múltiples instancias de condiciones de escritura fuera de límites pueden permitir que archivos maliciosos sean leídos y ejecutados por el software afectado.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Delta Industrial Automation PMSoft. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the processing of ppm files. The issue lies in the failure to properly validate user-supplied data which can result in a write outside the bounds of an allocated data structure. An attacker can leverage this vulnerability to execute arbitrary code under the context of current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-06-23 CVE Reserved
- 2016-12-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/94887 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-16-348-03 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Delta Electronics Search vendor "Delta Electronics" | Ispsoft Search vendor "Delta Electronics" for product "Ispsoft" | - | - |
Affected
| ||||||
Delta Electronics Search vendor "Delta Electronics" | Pmsoft Search vendor "Delta Electronics" for product "Pmsoft" | - | - |
Affected
| ||||||
Delta Electronics Search vendor "Delta Electronics" | Wplsoft Search vendor "Delta Electronics" for product "Wplsoft" | - | - |
Affected
|