Rewterz
Multiple Cisco Products Vulnerabilities
November 8, 2024
Rewterz
Multiple IBM Products Vulnerabilities
November 8, 2024

ICS: Multiple Delta Electronics DIAScreen Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-47131 CVSS:7.8

Delta Electronics DIAScreen is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the BACnetObjectInfo function. By persuading a victim to open a specially crafted file, a remote attacker could overflow a buffer and execute arbitrary code on the system.

CVE-2024-39605 CVSS:7.8

Delta Electronics DIAScreen is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the BACnetParameter function. By persuading a victim to open a specially crafted file, a remote attacker could overflow a buffer and execute arbitrary code on the system.

CVE-2024-39354 CVSS:7.8

Delta Electronics DIAScreen is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the CEtherIPTagItem function. By persuading a victim to open a specially crafted file, a remote attacker could overflow a buffer and execute arbitrary code on the system.

Impact

  • Buffer Overflow

Indicators of Compromise

CVE

  • CVE-2024-47131
  • CVE-2024-39605
  • CVE-2024-39354

Affected Vendors

Delta

Affected Products

  • Delta Electronics DIAScreen

Remediation

Upgrade to the latest version of DIAScreen, available from the Delta Electronics Website.

Delta Electronics Website