CVE-2019-10949
CVE-2019-10949
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 Apr 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnerabilities may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files.
Affected products
n/a · Delta Industrial Automation CNCSoftWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01https://www.zerodayinitiative.com/advisories/ZDI-19-406/https://www.zerodayinitiative.com/advisories/ZDI-19-407/https://www.zerodayinitiative.com/advisories/ZDI-19-409/https://www.zerodayinitiative.com/advisories/ZDI-19-411/https://www.zerodayinitiative.com/advisories/ZDI-19-412/https://www.zerodayinitiative.com/advisories/ZDI-19-413/https://www.zerodayinitiative.com/advisories/ZDI-19-414/https://www.zerodayinitiative.com/advisories/ZDI-19-415/https://www.zerodayinitiative.com/advisories/ZDI-19-416/https://www.zerodayinitiative.com/advisories/ZDI-19-418/https://www.zerodayinitiative.com/advisories/ZDI-19-419/