CVE-2021-38406
Description
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.
Summary dbcve.org
Delta Electronic DOPSoft 2 versions 2.00.07 and prior contain a file parsing vulnerability where user-supplied data in project files is not properly validated, leading to multiple out-of-bounds write conditions that can be exploited for arbitrary code execution in the context of the running process.
Mitigation
Restrict handling of untrusted DOPSoft project files; isolate the application from untrusted network sources; monitor vendor for security updates that address the parsing validation flaws.