CVE Feed

    Dashboard / CVE / CVE-2018-10594

    CVE-2018-10594

    Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.

    Published:Jun 26, 2018
    Last Modified:Nov 21, 2024
    EPS:Jun 26, 2018
    EPSS Score:0.78809
    CVSS Score:9.8

    Affected Products

    Vendor
    Deltaww
    Product
    Commgr
    Vendor
    Deltaww
    Product
    Dvpsimulator Ahsim 5x0
    Vendor
    Deltaww
    Product
    Dvpsimulator Ahsim 5x1
    Vendor
    Deltaww
    Product
    Dvpsimulator Eh2
    Vendor
    Deltaww
    Product
    Dvpsimulator Es2
    Vendor
    Deltaww
    Product
    Dvpsimulator H3
    Vendor
    Deltaww
    Product
    Dvpsimulator Se
    Vendor
    Deltaww
    Product
    Dvpsimulator Ss2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High