Delta Electronics CNCSoft-G2 (Update A)
Delta Electronics CNCSoft-G2 versions 2.0.0.5 and earlier than 2.1.0.20 contain multiple buffer overflow vulnerabilities (CWE-121, CWE-787, CWE-125, CWE-122) that could allow remote code execution if a user opens a malicious file. The vulnerabilities are not remotely exploitable over the network but require local user interaction—specifically, opening a crafted file in the application. Successful exploitation would grant an attacker code execution on the engineering workstation with the ability to modify CNC machine programs and parameters.
- User interaction required - engineer must open a malicious file in CNCSoft-G2
- Access to send file to target user (email, file share, USB)
- Vulnerable version of CNCSoft-G2 installed (2.0.0.5 or ≤2.1.0.10)
- CNCSoft-G2 must be running on the engineer's workstation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/95936690-99ea-41d0-86ec-e174e198719dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.