← Vulnerability feed

Vulnerability record · CVE-2023-24014 · published 7 June 2023

CVE-2023-24014: Deltaww cncsoft-b heap-based buffer overflow vulnerability

Deltaww · Cncsoft B

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

7.8 CVSS 3.1 High EPSS 0.23% · top 87.6% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/news-events/ics-advisories/icsa-23-157-01 PatchThird Party AdvisoryUS Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-157-01 PatchThird Party AdvisoryUS Government Resource

Track CVE-2023-24014 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-1941Deltaww cncsoft-b stack-based buffer overflow vulnerabilityDelta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitr…EPSS 0.74%7.8CVE-2024-1595Deltaww cncsoft-b uncontrolled search path element vulnerabilityDelta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the…EPSS 0.39%7.8CVE-2023-4685Deltaww cncsoft-b stack-based buffer overflow vulnerabilityDelta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffer overflow, which could allow…EPSS 0.23%7.8CVE-2023-25177Deltaww cncsoft-b stack-based buffer overflow vulnerabilityDelta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execu…EPSS 0.35%7.8CVE-2020-27287Deltaww cncsoft-b out-of-bounds write vulnerabilityDelta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an att…EPSS 2.5%7.8CVE-2020-27289Deltaww cncsoft-b null pointer dereference vulnerabilityDelta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project files, which may allow an attack…EPSS 1.9%7.8CVE-2020-27291Deltaww cncsoft-b out-of-bounds read vulnerabilityDelta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while processing project files, which may allow an atta…EPSS 1.9%7.8CVE-2020-27293Deltaww cncsoft-b type confusion vulnerabilityDelta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which may allow an attacker to exec…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2023-24014), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.