{"api_version":"1","generated_at":"2026-07-24T18:24:42+00:00","cve":"CVE-2018-17927","urls":{"html":"https://cve.report/CVE-2018-17927","api":"https://cve.report/api/cve/CVE-2018-17927.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-17927","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-17927"},"summary":{"title":"CVE-2018-17927","description":"In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2018-10-11 22:29:00","updated_at":"2019-10-09 23:37:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/105682","name":"105682","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-284-03","name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-284-03","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"Delta Industrial Automation TPEditor | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-17927","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-17927","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"17927","vulnerable":"1","versionEndIncluding":"1.90","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"deltaww","cpe5":"tpeditor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","DATE_PUBLIC":"2018-10-11T00:00:00","ID":"CVE-2018-17927","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Delta Industrial Automation TPEditor","version":{"version_data":[{"version_value":"TPEditor Versions 1.90 and prior."}]}}]},"vendor_name":"Delta Electronics"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"OUT-OF-BOUNDS WRITE CWE-787"}]}]},"references":{"reference_data":[{"name":"105682","refsource":"BID","url":"http://www.securityfocus.com/bid/105682"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-284-03","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-284-03"}]}},"nvd":{"publishedDate":"2018-10-11 22:29:00","lastModifiedDate":"2019-10-09 23:37:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:deltaww:tpeditor:*:*:*:*:*:*:*:*","versionEndIncluding":"1.90","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"17927","Ordinal":"134744","Title":"CVE-2018-17927","CVE":"CVE-2018-17927","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"17927","Ordinal":"1","NoteData":"In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"17927","Ordinal":"2","NoteData":"2018-10-11","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"17927","Ordinal":"3","NoteData":"2018-10-23","Type":"Other","Title":"Modified"}]}}}