ID

VAR-202506-0699


CVE

CVE-2025-47724


TITLE

Delta Electronics CNCSoft Screen Editor DPB File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Trust: 0.7

sources: ZDI: ZDI-25-469

DESCRIPTION

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of DPB files by the Screen Editor module. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. Delta Electronics CNCSoft is a CNC machine simulation system software from Delta Electronics, a Chinese company

Trust: 2.07

sources: NVD: CVE-2025-47724 // ZDI: ZDI-25-469 // CNVD: CNVD-2025-12363

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-12363

AFFECTED PRODUCTS

vendor:deltamodel:cncsoftscope: - version: -

Trust: 0.7

vendor:deltamodel:electronics cncsoftscope:lteversion:<=v1.01.34

Trust: 0.6

sources: ZDI: ZDI-25-469 // CNVD: CNVD-2025-12363

CVSS

SEVERITY

CVSSV2

CVSSV3

759f5e80-c8e1-4224-bead-956d7b33c98b: CVE-2025-47724
value: HIGH

Trust: 1.0

ZDI: CVE-2025-47724
value: HIGH

Trust: 0.7

CNVD: CNVD-2025-12363
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-12363
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

ZDI: CVE-2025-47724
baseSeverity: HIGH
baseScore: 7.8
vectorString: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-25-469 // CNVD: CNVD-2025-12363 // NVD: CVE-2025-47724

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

sources: NVD: CVE-2025-47724

PATCH

title:Delta Electronics has issued an update to correct this vulnerability.url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-175-02

Trust: 0.7

sources: ZDI: ZDI-25-469

EXTERNAL IDS

db:NVDid:CVE-2025-47724

Trust: 2.3

db:ZDI_CANid:ZDI-CAN-26718

Trust: 0.7

db:ZDIid:ZDI-25-469

Trust: 0.7

db:CNVDid:CNVD-2025-12363

Trust: 0.6

sources: ZDI: ZDI-25-469 // CNVD: CNVD-2025-12363 // NVD: CVE-2025-47724

REFERENCES

url:https://filecenter.deltaww.com/news/download/doc/delta-pcsa-2025-00006_cncsoft%20-%20out-of-bounds%20write.pdf

Trust: 1.6

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-175-02

Trust: 0.7

sources: ZDI: ZDI-25-469 // CNVD: CNVD-2025-12363 // NVD: CVE-2025-47724

CREDITS

Natnael Samson (@NattiSamson)

Trust: 0.7

sources: ZDI: ZDI-25-469

SOURCES

db:ZDIid:ZDI-25-469
db:CNVDid:CNVD-2025-12363
db:NVDid:CVE-2025-47724

LAST UPDATE DATE

2025-07-05T23:12:31.163000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-25-469date:2025-07-03T00:00:00
db:CNVDid:CNVD-2025-12363date:2025-06-13T00:00:00
db:NVDid:CVE-2025-47724date:2025-06-04T14:54:33.783

SOURCES RELEASE DATE

db:ZDIid:ZDI-25-469date:2025-07-03T00:00:00
db:CNVDid:CNVD-2025-12363date:2025-06-13T00:00:00
db:NVDid:CVE-2025-47724date:2025-06-04T08:15:21.867