Delta Electronics CNCSoft-G2 DOPSoft (Update A)
A buffer overflow vulnerability in Delta Electronics CNCSoft-G2 exists that allows arbitrary code execution when a user opens a malicious file in the application. The vulnerability affects CNCSoft-G2 versions 2.0.0.5 with DOPSoft v5.0.0.93 and 2.1.0.27 or earlier. This is not remotely exploitable and requires local access and user interaction to trigger. An attacker with ability to deliver a crafted file to an engineering workstation could execute code with the application's privileges, potentially modifying CNC programs or machine parameters.
- Local access to the machine running CNCSoft-G2
- User interaction required (opening a malicious file or input)
- Vulnerable version of CNCSoft-G2 installed (2.0.0.5 with DOPSoft v5.0.0.93 or 2.1.0.27 or earlier)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/d3feabdf-681e-49ec-9e6a-192cce400600Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.