CVE-2024-1595

HIGH

Deltaww Cncsoft-b < 1.0.0.4 - Uncontrolled Search Path

Title source: rule

Description

Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 6.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (2)

deltaww/cncsoft-b < 1.0.0.4
deltaww/dopsoft < 4.0.0.94

Timeline

Published Feb 29, 2024
Tracked Since Feb 18, 2026