peter bassill · operator
$ cve CVE-2018-10594 JSON

CVE-2018-10594 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 68.6% (pctl 99)

Patch early

A public exploit exists.

Description

Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS68.62% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-121
On CISA KEVno
Public exploityes
Published2018-06-26
Last modified2026-06-17

Affected (8)

VendorProduct
deltawwcommgr
deltawwdvpsimulator ahsim 5x0
deltawwdvpsimulator ahsim 5x1
deltawwdvpsimulator eh2
deltawwdvpsimulator es2
deltawwdvpsimulator h3
deltawwdvpsimulator se
deltawwdvpsimulator ss2

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD