#VU20351 Use-after-free in Delta Industrial Automation DOPSoft - CVE-2019-13514 

 

#VU20351 Use-after-free in Delta Industrial Automation DOPSoft - CVE-2019-13514

Published: August 21, 2019


Vulnerability identifier: #VU20351
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-13514
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Delta Industrial Automation DOPSoft
Software vendor:
Delta Electronics, Inc.

Description

The vulnerability allows a local attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing a specially crafted project file. A local attacker can send a specially crafted project file, trigger a use-after-free vulnerability, gain sensitive information on the target system, execute arbitrary code, or crash the application.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Remediation

Install updates from vendor's website.

External links