Successful exploitation of these vulnerabilities, discovered by Natnael Samson (@NattiSamson) working with Trend Micro’s Zero Day Initiative, could allow for remote code execution.
Versions 4.00.16.22 and prior of DOPSoft, a human machine interface (HMI) editing software suffer from the vulnerabilities.
In one issue, Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.
CVE-2023-0123 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.
In addition, Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.
CVE-2023-0124 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target these vulnerabilities. These vulnerabilities are not exploitable remotely. However, an attacker with low skill level could leverage these low complexity vulnerabilities.
Taiwan-based Delta Electronics released version 1.3.0 of DIAScreen (login required) and recommends users to use DIAScreen instead of DOPSoft.

