Delta Electronics CNCSoft-G2 Version 2.1.0.16 and prior lacks proper
validation of the length of user-supplied data prior to copying it to a
fixed-length heap-based buffer. If a target visits a malicious page or
opens a malicious file an attacker can leverage this vulnerability to
execute code in the context of the current process.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 13 Mar 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Delta Electronics CNCSoft-G2 Version 2.1.0.16 and prior lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process. | |
Title | Delta Electronics CNCSoft-G2 Heap-based Buffer Overflow | |
Weaknesses | CWE-122 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-03-13T16:47:43.636Z
Updated: 2025-03-13T18:57:44.247Z
Reserved: 2024-12-20T16:52:15.306Z
Link: CVE-2024-12858

Updated: 2025-03-13T18:57:40.736Z

Status : Received
Published: 2025-03-13T17:15:25.653
Modified: 2025-03-13T17:15:25.653
Link: CVE-2024-12858

No data.