Vulnerabilities > CVE-2020-27280 - Use After Free vulnerability in Deltaww Ispsoft 3.0.5/3.0.6/3.12

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.

Vulnerable Configurations

Part Description Count
Application
Deltaww
3

Common Weakness Enumeration (CWE)