关键漏洞信息 CVE ID: CVE-2019-13513 CVSS Score: 7.8 Affected Vendor: Delta Industrial Automation Affected Product: DOPSoft Vulnerability Type: Out-Of-Bounds Read Remote Code Execution Vulnerability Vulnerability Details: - Allows remote attackers to execute arbitrary code on affected instances of Delta Industrial Automation DOPSoft. - Requires user interaction (visiting a malicious page or opening a malicious file). - Occurs due to lack of proper validation of user-supplied data, leading to a read before the start of an allocated buffer. Additional Details: Delta Industrial Automation has issued an update. More details at: https://www.us-cert.gov/ics/advisories/icsa-19-225-01 Disclosure Timeline: - 2019-03-27: Vulnerability reported to vendor. - 2019-08-16: Coordinated public release of advisory. Credit: kimiya of 9SG Security Team - kimiya@9sgsec.com