SCADA Vulnerabilities & Exposures (SVE)

CRITIFENCE® SCADA Vulnerabilities and Exposures Database (SVE)

[SVE-205434487] Delta Electronics Delta Industrial Automation Screen Editor

Date Type Platform Author EDB-ID CVE-ID OSVDB-ID Download App SIS Signature
2018-01-04OtherDelta ElectronicsSteven Seeley of Source Incite reported these vulnerabilities to ICS-CERT.N/ACVE-2017-1675 CVE-2017-1674 CVE-2017-1674 CVE-2017-1674 N/AN/AN/A

Source

						
							
								
#
# Delta Electronics Delta Industrial Automation Screen Editor
#


### VULNERABLE VENDOR
Delta Electronics


### VULNERABLE PRODUCT
Delta Industrial Automation Screen Editor 


### RESEARCHER
Steven Seeley of Source Incite reported these vulnerabilities to ICS-CERT.


### AFFECTED PRODUCTS
The following versions of Delta Industrial Automation Screen Editor, a graphical user interface (GUI), are affected:

Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior


### IMPACT
Successful exploitation of these vulnerabilities may allow an attacker to remotely execute arbitrary code.


### VULNERABILITY OVERVIEW
STACK-BASED BUFFER OVERFLOW CWE-121
Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dpb files may allow an attacker to remotely execute arbitrary code.
CVE-2017-16751 has been assigned to this vulnerability.
A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)


USE-AFTER-FREE CWE-416
Specially crafted .dpb files could exploit a use-after-free vulnerability.
CVE-2017-16749 has been assigned to this vulnerability.
A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)


OUT-OF-BOUNDS WRITE CWE-787
Specially crafted .dpb files may cause the system to write outside the intended buffer area.
CVE-2017-16747 has been assigned to this vulnerability.
A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)


ACCESS OF RESOURCE USING INCOMPATIBLE TYPE ('TYPE CONFUSION') CWE-843
An access of resource using incompatible type (‘type confusion’) vulnerability may allow an attacker to execute remote code when processing specially crafted .dpb files.
CVE-2017-16745 has been assigned to this vulnerability.
A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)





### BACKGROUND
Critical Infrastructure Sector: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Taiwan




### MITIGATION

Delta Electronics recommends affected users update to the latest version of DOPSoft Version 2, which is available for download at:

http://


www.deltaww.com/Products/PluginWebUserControl/downloadCenterCounter.aspx?DID=9313&DocPath=1&hl=en-US


.

Delta Industrial Automation Screen Editor Version 2.00.23.00 has been removed from Delta Electronics’ web site and replaced with DOPSoft, Version 2. Delta Electronics also recommends that users restrict the interaction with the application to trusted files.