PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-4192 Delta Electronics CVE debrief

Delta Electronics CNCSoft-G2 contains a stack-based buffer overflow vulnerability due to improper validation of user-supplied data length before copying to a fixed-length buffer. This local attack vector allows code execution in the context of the current process. The vulnerability was disclosed in April 2024 and updated in October 2025 to reflect modified affected products and mitigations. Affected versions are CNCSoft-G2 2.0.0.5 and earlier with DOPSoft v5.0.0.93. Delta Electronics has released version 2.1.0.4 to address this issue.

Vendor
Delta Electronics
Product
CNCSoft-G2
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-30
Original CVE updated
2025-10-16
Advisory published
2024-04-30
Advisory updated
2025-10-16

Who should care

Organizations using Delta Electronics CNCSoft-G2 for HMI configuration in industrial automation environments, particularly manufacturing facilities with Delta DOP series operator panels. Security teams responsible for OT/ICS asset management and patch deployment should prioritize this update due to the high impact potential and availability of a vendor fix.

Technical summary

CVE-2024-4192 is a stack-based buffer overflow in Delta Electronics CNCSoft-G2, an HMI (Human-Machine Interface) configuration software used with Delta DOP series touch panels. The vulnerability exists in file parsing functionality where user-supplied data length is not properly validated before being copied to a fixed-length stack buffer. Successful exploitation allows arbitrary code execution with the privileges of the current process. The attack requires local access and user interaction, with attack complexity rated as low. This vulnerability affects CNCSoft-G2 version 2.0.0.5 and earlier when used with DOPSoft v5.0.0.93. Delta Electronics released version 2.1.0.4 as a security update. The October 2025 advisory update modified affected product listings and mitigation guidance.

Defensive priority

HIGH

Recommended defensive actions

  • Update CNCSoft-G2 to version 2.1.0.4 or later to remediate this vulnerability
  • Review Delta Electronics published security advisory for additional technical details
  • Apply defense-in-depth practices for industrial control systems per CISA guidance
  • Restrict local access to engineering workstations running CNCSoft-G2
  • Monitor for anomalous process behavior on systems running affected versions

Evidence notes

CISA ICS advisory ICSA-24-121-01 (Update A) published 2024-04-30, modified 2025-10-16. CVSS 3.1 score 7.8 (HIGH). Vendor fix available in CNCSoft-G2 v2.1.0.4 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-4192 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-4192

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-4192 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-4192

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-121-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-121-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.