CVE-2019-10947
Last modified
CVE-2019-10947 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. EPSS estimates a 3.67% chance of exploitation in the next 30 days.
Description
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. This may occur because CNCSoft lacks user input validation before copying data from project files onto the stack.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Deltaww | Cncsoft Screeneditor | <= 1.00.88 |
References
- http://www.securityfocus.com/bid/107989Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01Patch, Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-19-399/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-400/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-401/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-402/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-403/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-404/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-410/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-417/Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107989Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01Patch, Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-19-399/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-400/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-401/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-402/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-403/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-404/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-410/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-19-417/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10947?
How severe is CVE-2019-10947?
How do I fix CVE-2019-10947?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10940A vulnerability has been identified in SINEMA Server (All ve…9.9
- CVE-2019-10941A vulnerability has been identified in SINEMA Server (All ve…5.3
- CVE-2019-10942A vulnerability has been identified in SCALANCE X-200 switch…8.6
- CVE-2019-10943A vulnerability has been identified in SIMATIC Drive Control…7.5
- CVE-2019-10945An issue was discovered in Joomla! before 3.9.5. The Media M…
- CVE-2019-10946An issue was discovered in Joomla! before 3.9.5. The "refres…
- CVE-2019-10948Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions C…
- CVE-2019-10949Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Ve…
- CVE-2019-1095An information disclosure vulnerability exists when the Wind…
- CVE-2019-10950Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions C…9.8
- CVE-2019-10951Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Ve…7.8
- CVE-2019-10952An attacker could send a crafted HTTP/HTTPS request to rende…9.8
Are you affected by CVE-2019-10947?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
