← All CVEs

CVE-2018-10594

critical · 9.8

Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.

9.8
CVSS
68.6%
EPSS (exploit prob.)
99th
EPSS percentile
2018-06-26
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-121CWE-119

Affected products

VendorProductAffected versions
deltawwcommgr<= 1.08
deltawwdvpsimulator_ahsim_5x0all versions
deltawwdvpsimulator_ahsim_5x1all versions
deltawwdvpsimulator_eh2all versions
deltawwdvpsimulator_es2all versions
deltawwdvpsimulator_h3all versions
deltawwdvpsimulator_seall versions
deltawwdvpsimulator_ss2all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-10594