CVE-2024-47962

Publication date

2024-10-10 17:14:30

Family

icscert

State

PUBLISHED

Description

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.