Number: AV18-127
Date: 08 August 2018
Purpose
The purpose of this advisory is to bring attention to vulnerabilities affecting Delta Electronics CNCSoft and ScreenEditor.
Assessment
A security update has been released to address vulnerabilities in CNCSoft and ScreenEditor. Successful exploitation of these vulnerabilities could allow an attacker to gain administrator privileges and perform remote code execution.
Affected Products:
- CNCSoft Version 1.00.83 and prior
- ScreenEditor Version 1.00.54
CVE References: CVE-2018-10598, CVE-2018-10636
Suggested action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. For more information, please refer to the ICS-CERT references.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-10598
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-10636
https://ics-cert.us-cert.gov/advisories/ICSA-18-219-01