CVE-2018-10594
high-risk
Published 2018-06-26
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.
Do I need to act?
!
78.2% chance of exploitation in next 30 days
EPSS score — higher than 22% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (8)
Third Party Advisory
http://www.securityfocus.com/bid/104529
Third Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-18-172-01
Third Party Advisory
http://www.securityfocus.com/bid/104529
Third Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-18-172-01
64
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
27/34 · High
Exposure
5/34 · Minimal