deltaww CVE Vulnerabilities & Metrics

Focus on deltaww vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About deltaww Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with deltaww. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total deltaww CVEs: 228
Earliest CVE date: 15 Mar 2018, 23:29 UTC
Latest CVE date: 11 Nov 2024, 15:15 UTC

Latest CVE reference: CVE-2024-47131

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 21

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -48.78%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -48.78%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical deltaww CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.18

Max CVSS: 10.0

Critical CVEs (≥9): 33

CVSS Range vs. Count

Range Count
0.0-3.9 99
4.0-6.9 84
7.0-8.9 12
9.0-10.0 33

CVSS Distribution Chart

Top 5 Highest CVSS deltaww CVEs

These are the five CVEs with the highest CVSS scores for deltaww, sorted by severity first and recency.

All CVEs for deltaww

CVE-2024-47131 deltaww vulnerability CVSS: 0 11 Nov 2024, 15:15 UTC

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetObjectInfo can be exploited, allowing the attacker to remotely execute arbitrary code.

CVE-2024-39605 deltaww vulnerability CVSS: 0 11 Nov 2024, 15:15 UTC

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetParameter can be exploited, allowing the attacker to remotely execute arbitrary code.

CVE-2024-39354 deltaww vulnerability CVSS: 0 11 Nov 2024, 15:15 UTC

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in CEtherIPTagItem can be exploited, allowing the attacker to remotely execute arbitrary code.

CVE-2024-47966 deltaww vulnerability CVSS: 0 10 Oct 2024, 18:15 UTC

Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

CVE-2024-47965 deltaww vulnerability CVSS: 0 10 Oct 2024, 18:15 UTC

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

CVE-2024-47964 deltaww vulnerability CVSS: 0 10 Oct 2024, 18:15 UTC

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

CVE-2024-47963 deltaww vulnerability CVSS: 0 10 Oct 2024, 18:15 UTC

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

CVE-2024-47962 deltaww vulnerability CVSS: 0 10 Oct 2024, 18:15 UTC

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

CVE-2024-43699 deltaww vulnerability CVSS: 0 03 Oct 2024, 23:15 UTC

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product.

CVE-2024-42417 deltaww vulnerability CVSS: 0 03 Oct 2024, 23:15 UTC

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.

CVE-2024-7502 deltaww vulnerability CVSS: 0 06 Aug 2024, 17:15 UTC

A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

CVE-2024-39883 deltaww vulnerability CVSS: 0 09 Jul 2024, 22:15 UTC

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

CVE-2024-39882 deltaww vulnerability CVSS: 0 09 Jul 2024, 22:15 UTC

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

CVE-2024-39881 deltaww vulnerability CVSS: 0 09 Jul 2024, 22:15 UTC

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

CVE-2024-39880 deltaww vulnerability CVSS: 0 09 Jul 2024, 22:15 UTC

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

CVE-2024-34033 deltaww vulnerability CVSS: 0 03 May 2024, 01:15 UTC

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

CVE-2024-34032 deltaww vulnerability CVSS: 0 03 May 2024, 01:15 UTC

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

CVE-2024-34031 deltaww vulnerability CVSS: 0 03 May 2024, 01:15 UTC

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

CVE-2024-25574 deltaww vulnerability CVSS: 0 01 Apr 2024, 16:15 UTC

SQL injection vulnerability exists in GetDIAE_usListParameters.

CVE-2024-28029 deltaww vulnerability CVSS: 0 21 Mar 2024, 22:15 UTC

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

CVE-2024-25937 deltaww vulnerability CVSS: 0 21 Mar 2024, 22:15 UTC

SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

CVE-2023-5131 deltaww vulnerability CVSS: 7.3 18 Jan 2024, 22:15 UTC

A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

CVE-2023-5130 deltaww vulnerability CVSS: 7.3 18 Jan 2024, 22:15 UTC

A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

CVE-2023-43824 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

CVE-2023-43823 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

CVE-2023-43822 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

CVE-2023-43821 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

CVE-2023-43820 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

CVE-2023-43819 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

CVE-2023-43818 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

CVE-2023-43817 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

CVE-2023-43816 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

CVE-2023-43815 deltaww vulnerability CVSS: 6.8 18 Jan 2024, 22:15 UTC

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

CVE-2023-5944 deltaww vulnerability CVSS: 0 04 Dec 2023, 23:15 UTC

Delta Electronics DOPSoft is vulnerable to a stack-based buffer overflow, which may allow for arbitrary code execution if an attacker can lead a legitimate user to execute a specially crafted file.

CVE-2023-47279 deltaww vulnerability CVSS: 0 30 Nov 2023, 23:15 UTC

In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.

CVE-2023-47207 deltaww vulnerability CVSS: 0 30 Nov 2023, 22:15 UTC

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.

CVE-2023-46690 deltaww vulnerability CVSS: 0 30 Nov 2023, 22:15 UTC

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.

CVE-2023-39226 deltaww vulnerability CVSS: 0 30 Nov 2023, 22:15 UTC

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.

CVE-2023-5461 deltaww vulnerability CVSS: 2.6 09 Oct 2023, 20:15 UTC

A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241584. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5460 deltaww vulnerability CVSS: 2.7 09 Oct 2023, 19:15 UTC

A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some unknown processing of the component Modbus Data Packet Handler. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-241583. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5459 deltaww vulnerability CVSS: 6.1 09 Oct 2023, 19:15 UTC

A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. VDB-241582 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5068 deltaww vulnerability CVSS: 0 21 Sep 2023, 23:15 UTC

Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file. This could allow an attacker to execute code in the context of the current process.

CVE-2023-4685 deltaww vulnerability CVSS: 0 07 Sep 2023, 18:15 UTC

Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVE-2023-34316 deltaww vulnerability CVSS: 0 10 Jul 2023, 20:15 UTC

​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.

CVE-2023-30765 deltaww vulnerability CVSS: 0 10 Jul 2023, 20:15 UTC

​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.

CVE-2023-34347 deltaww vulnerability CVSS: 0 10 Jul 2023, 19:15 UTC

​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.

CVE-2023-25177 deltaww vulnerability CVSS: 0 07 Jun 2023, 21:15 UTC

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVE-2023-24014 deltaww vulnerability CVSS: 0 07 Jun 2023, 21:15 UTC

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVE-2023-0432 deltaww vulnerability CVSS: 0 31 Mar 2023, 16:15 UTC

The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web service, then the device could be fully compromised.

CVE-2023-1145 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

CVE-2023-1144 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.

CVE-2023-1143 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.

CVE-2023-1142 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.

CVE-2023-1141 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution.

CVE-2023-1140 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.

CVE-2023-1139 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

CVE-2023-1138 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.

CVE-2023-1137 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.

CVE-2023-1136 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.

CVE-2023-1135 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.

CVE-2023-1134 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.

CVE-2023-1133 deltaww vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

CVE-2023-0822 deltaww vulnerability CVSS: 0 17 Feb 2023, 17:15 UTC

The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.

CVE-2023-0251 deltaww vulnerability CVSS: 0 08 Feb 2023, 23:15 UTC

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restrictions of operations within memory, which could allow an attacker to remotely execute arbitrary code.

CVE-2023-0250 deltaww vulnerability CVSS: 0 08 Feb 2023, 23:15 UTC

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.

CVE-2023-0249 deltaww vulnerability CVSS: 0 08 Feb 2023, 23:15 UTC

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

CVE-2023-0124 deltaww vulnerability CVSS: 0 03 Feb 2023, 03:15 UTC

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

CVE-2023-0123 deltaww vulnerability CVSS: 0 03 Feb 2023, 03:15 UTC

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

CVE-2022-4634 deltaww vulnerability CVSS: 0 03 Feb 2023, 03:15 UTC

All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.

CVE-2023-0444 deltaww vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator.

CVE-2022-4616 deltaww vulnerability CVSS: 0 13 Jan 2023, 00:15 UTC

The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions.

CVE-2022-41778 deltaww vulnerability CVSS: 0 13 Jan 2023, 00:15 UTC

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.

CVE-2022-2966 deltaww vulnerability CVSS: 0 16 Dec 2022, 20:15 UTC

Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.

CVE-2022-42141 deltaww vulnerability CVSS: 0 14 Dec 2022, 00:15 UTC

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.

CVE-2022-42140 deltaww vulnerability CVSS: 0 14 Dec 2022, 00:15 UTC

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

CVE-2022-42139 deltaww vulnerability CVSS: 0 14 Dec 2022, 00:15 UTC

Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

CVE-2022-2660 deltaww vulnerability CVSS: 0 13 Dec 2022, 22:15 UTC

Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.

CVE-2022-2969 deltaww vulnerability CVSS: 0 01 Dec 2022, 18:15 UTC

Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.

CVE-2022-43506 deltaww vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

CVE-2022-43457 deltaww vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

CVE-2022-43452 deltaww vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

CVE-2022-43447 deltaww vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

CVE-2022-41775 deltaww vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

CVE-2022-41779 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution.

CVE-2022-41776 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the changing of administrative passwords.

CVE-2022-41772 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.

CVE-2022-41688 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group.

CVE-2022-41657 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations and could ultimately result in remote code execution.

CVE-2022-41644 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their own privileges.

CVE-2022-41629 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.

CVE-2022-40202 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution.

CVE-2022-38142 deltaww vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.

CVE-2022-41773 deltaww vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

CVE-2022-41702 deltaww vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.

CVE-2022-41701 deltaww vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.

CVE-2022-41651 deltaww vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.

CVE-2022-41555 deltaww vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.

CVE-2022-41133 deltaww vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

CVE-2022-40967 deltaww vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

CVE-2022-40965 deltaww vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.

CVE-2022-43775 deltaww vulnerability CVSS: 0 26 Oct 2022, 18:15 UTC

The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

CVE-2022-43774 deltaww vulnerability CVSS: 0 26 Oct 2022, 18:15 UTC

The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

CVE-2022-3214 deltaww vulnerability CVSS: 0 16 Sep 2022, 19:15 UTC

Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.

CVE-2022-2759 deltaww vulnerability CVSS: 0 31 Aug 2022, 16:15 UTC

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

CVE-2022-1405 deltaww vulnerability CVSS: 0 31 Aug 2022, 16:15 UTC

CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buffer overflow condition.

CVE-2022-1404 deltaww vulnerability CVSS: 0 31 Aug 2022, 16:15 UTC

Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

CVE-2022-33005 deltaww vulnerability CVSS: 4.3 27 Jun 2022, 21:15 UTC

A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.

CVE-2022-1378 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1377 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1376 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1375 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1374 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1372 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1371 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1370 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1369 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1367 deltaww vulnerability CVSS: 10.0 02 May 2022, 19:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1366 deltaww vulnerability CVSS: 10.0 02 May 2022, 18:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-1403 deltaww vulnerability CVSS: 6.8 29 Apr 2022, 17:15 UTC

ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds write condition.

CVE-2022-1402 deltaww vulnerability CVSS: 5.8 29 Apr 2022, 17:15 UTC

ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

CVE-2022-1098 deltaww vulnerability CVSS: 4.4 01 Apr 2022, 23:15 UTC

Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges

CVE-2022-27175 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26887 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_loopmapHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26839 deltaww vulnerability CVSS: 4.6 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.

CVE-2022-26836 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26667 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetDemandAnalysisData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26666 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerECC.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26514 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_tagHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26349 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_eccoefficientHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26338 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerPageP_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26069 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26065 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in GetLatestDemandNode. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26059 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetQueryData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-26013 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-25980 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-25880 deltaww vulnerability CVSS: 10.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-25347 deltaww vulnerability CVSS: 5.0 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

CVE-2022-0923 deltaww vulnerability CVSS: 7.5 29 Mar 2022, 17:15 UTC

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

CVE-2022-0988 deltaww vulnerability CVSS: 5.0 25 Mar 2022, 19:15 UTC

Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.

CVE-2021-44768 deltaww vulnerability CVSS: 4.3 25 Mar 2022, 19:15 UTC

Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.

CVE-2021-44544 deltaww vulnerability CVSS: 4.3 22 Dec 2021, 19:15 UTC

DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”.

CVE-2021-44471 deltaww vulnerability CVSS: 4.3 22 Dec 2021, 19:15 UTC

DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.

CVE-2021-31558 deltaww vulnerability CVSS: 4.3 22 Dec 2021, 19:15 UTC

DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.

CVE-2021-23228 deltaww vulnerability CVSS: 4.3 22 Dec 2021, 19:15 UTC

DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.

CVE-2021-43982 deltaww vulnerability CVSS: 6.8 09 Dec 2021, 22:15 UTC

Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

CVE-2021-38488 deltaww vulnerability CVSS: 3.5 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.

CVE-2021-38428 deltaww vulnerability CVSS: 3.5 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.

CVE-2021-38424 deltaww vulnerability CVSS: 6.8 03 Nov 2021, 20:15 UTC

The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

CVE-2021-38422 deltaww vulnerability CVSS: 4.6 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.

CVE-2021-38420 deltaww vulnerability CVSS: 4.6 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

CVE-2021-38418 deltaww vulnerability CVSS: 4.3 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.

CVE-2021-38416 deltaww vulnerability CVSS: 4.4 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.

CVE-2021-38411 deltaww vulnerability CVSS: 3.5 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.

CVE-2021-38407 deltaww vulnerability CVSS: 3.5 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.

CVE-2021-38403 deltaww vulnerability CVSS: 3.5 03 Nov 2021, 20:15 UTC

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.

CVE-2021-38406 deltaww vulnerability CVSS: 6.8 17 Sep 2021, 19:15 UTC

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.

CVE-2021-38404 deltaww vulnerability CVSS: 6.8 17 Sep 2021, 19:15 UTC

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

CVE-2021-38402 deltaww vulnerability CVSS: 6.8 17 Sep 2021, 19:15 UTC

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage this vulnerability to execute code in the context of the current process.

CVE-2021-38393 deltaww vulnerability CVSS: 10.0 30 Aug 2021, 18:15 UTC

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVE-2021-38391 deltaww vulnerability CVSS: 10.0 30 Aug 2021, 18:15 UTC

A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVE-2021-38390 deltaww vulnerability CVSS: 10.0 30 Aug 2021, 18:15 UTC

A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVE-2021-33019 deltaww vulnerability CVSS: 6.8 30 Aug 2021, 18:15 UTC

A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

CVE-2021-33007 deltaww vulnerability CVSS: 6.8 30 Aug 2021, 18:15 UTC

A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code.

CVE-2021-33003 deltaww vulnerability CVSS: 2.1 30 Aug 2021, 18:15 UTC

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

CVE-2021-32991 deltaww vulnerability CVSS: 4.3 30 Aug 2021, 18:15 UTC

Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.

CVE-2021-32983 deltaww vulnerability CVSS: 10.0 30 Aug 2021, 18:15 UTC

A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.

CVE-2021-32967 deltaww vulnerability CVSS: 10.0 30 Aug 2021, 18:15 UTC

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.

CVE-2021-32955 deltaww vulnerability CVSS: 7.5 30 Aug 2021, 18:15 UTC

Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

CVE-2021-27455 deltaww vulnerability CVSS: 4.3 02 Jul 2021, 11:15 UTC

Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.

CVE-2021-27412 deltaww vulnerability CVSS: 6.8 02 Jul 2021, 11:15 UTC

Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.

CVE-2021-22668 deltaww vulnerability CVSS: 7.5 16 May 2021, 15:15 UTC

Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.

CVE-2021-22672 deltaww vulnerability CVSS: 6.8 10 May 2021, 13:15 UTC

Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.

CVE-2020-27288 deltaww vulnerability CVSS: 6.8 26 Jan 2021, 18:15 UTC

An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

CVE-2020-27284 deltaww vulnerability CVSS: 6.8 26 Jan 2021, 18:15 UTC

TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

CVE-2020-27280 deltaww vulnerability CVSS: 6.8 26 Jan 2021, 18:15 UTC

A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.

CVE-2020-27293 deltaww vulnerability CVSS: 6.8 11 Jan 2021, 16:15 UTC

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which may allow an attacker to execute arbitrary code.

CVE-2020-27291 deltaww vulnerability CVSS: 6.8 11 Jan 2021, 16:15 UTC

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.

CVE-2020-27289 deltaww vulnerability CVSS: 6.8 11 Jan 2021, 16:15 UTC

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

CVE-2020-27287 deltaww vulnerability CVSS: 6.8 11 Jan 2021, 16:15 UTC

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

CVE-2020-27281 deltaww vulnerability CVSS: 6.8 11 Jan 2021, 16:15 UTC

A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.

CVE-2020-27277 deltaww vulnerability CVSS: 9.3 11 Jan 2021, 16:15 UTC

Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

CVE-2020-27275 deltaww vulnerability CVSS: 9.3 11 Jan 2021, 16:15 UTC

Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

CVE-2020-16227 deltaww vulnerability CVSS: 6.8 07 Aug 2020, 00:15 UTC

Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by processing a specially crafted project file not validated when the data is entered by a user. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-16225 deltaww vulnerability CVSS: 6.8 07 Aug 2020, 00:15 UTC

Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-16223 deltaww vulnerability CVSS: 6.8 07 Aug 2020, 00:15 UTC

Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-16221 deltaww vulnerability CVSS: 6.8 07 Aug 2020, 00:15 UTC

Delta Electronics TPEditor Versions 1.97 and prior. A stack-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-16219 deltaww vulnerability CVSS: 6.8 07 Aug 2020, 00:15 UTC

Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by processing specially crafted project files. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-16203 deltaww vulnerability CVSS: 6.8 04 Aug 2020, 19:15 UTC

Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-16201 deltaww vulnerability CVSS: 4.3 04 Aug 2020, 19:15 UTC

Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information.

CVE-2020-16199 deltaww vulnerability CVSS: 6.8 04 Aug 2020, 19:15 UTC

Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-14482 deltaww vulnerability CVSS: 6.8 30 Jun 2020, 18:15 UTC

Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

CVE-2020-10597 deltaww vulnerability CVSS: 5.8 20 Mar 2020, 15:15 UTC

Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information and/or crash the application.

CVE-2020-6976 deltaww vulnerability CVSS: 4.3 18 Mar 2020, 14:15 UTC

Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation.

CVE-2020-7002 deltaww vulnerability CVSS: 6.8 18 Mar 2020, 13:15 UTC

Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens a specially crafted, malicious input file.

CVE-2019-16247 deltaww vulnerability CVSS: 4.6 11 Sep 2019, 22:15 UTC

Delta DCISoft 1.21 has a User Mode Write AV starting at CommLib!CCommLib::SetSerializeData+0x000000000000001b.

CVE-2019-13544 deltaww vulnerability CVSS: 6.8 11 Sep 2019, 21:15 UTC

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files, which may allow remote code execution.

CVE-2019-13540 deltaww vulnerability CVSS: 6.8 11 Sep 2019, 21:15 UTC

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

CVE-2019-13536 deltaww vulnerability CVSS: 6.8 11 Sep 2019, 21:15 UTC

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

CVE-2019-13514 deltaww vulnerability CVSS: 6.8 15 Aug 2019, 19:15 UTC

In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may trigger a use-after-free vulnerability, which may allow information disclosure, remote code execution, or crash of the application.

CVE-2019-13513 deltaww vulnerability CVSS: 6.8 15 Aug 2019, 19:15 UTC

In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may trigger multiple out-of-bounds read vulnerabilities, which may allow information disclosure, remote code execution, or crash of the application.

CVE-2019-10992 deltaww vulnerability CVSS: 4.3 24 Jul 2019, 15:15 UTC

Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files.

CVE-2019-10982 deltaww vulnerability CVSS: 6.8 24 Jul 2019, 15:15 UTC

Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.

CVE-2019-12899 deltaww vulnerability CVSS: 7.5 19 Jun 2019, 22:15 UTC

Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem+0x00000000000005e3.

CVE-2019-12898 deltaww vulnerability CVSS: 7.5 19 Jun 2019, 22:15 UTC

Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000000017a45e.

CVE-2019-10951 deltaww vulnerability CVSS: 6.8 17 Apr 2019, 15:29 UTC

Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.

CVE-2019-10949 deltaww vulnerability CVSS: 4.3 17 Apr 2019, 15:29 UTC

Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnerabilities may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files.

CVE-2019-10947 deltaww vulnerability CVSS: 6.8 17 Apr 2019, 15:29 UTC

Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. This may occur because CNCSoft lacks user input validation before copying data from project files onto the stack.

CVE-2019-6547 deltaww vulnerability CVSS: 4.3 28 Feb 2019, 21:29 UTC

Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.84 and prior. An out-of-bounds read vulnerability may cause the software to crash due to lacking user input validation for processing project files.

CVE-2018-17929 deltaww vulnerability CVSS: 6.8 11 Oct 2018, 22:29 UTC

In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files lacking user input validation before copying data from project files onto the stack and may allow an attacker to remotely execute arbitrary code.

CVE-2018-17927 deltaww vulnerability CVSS: 6.8 11 Oct 2018, 22:29 UTC

In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution.

CVE-2018-14800 deltaww vulnerability CVSS: 6.8 03 Oct 2018, 13:29 UTC

Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application to read past the boundary allocated to a stack object, which could allow execution of code under the context of the application.

CVE-2018-14824 deltaww vulnerability CVSS: 4.3 27 Sep 2018, 20:29 UTC

Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be executed when processing project files, which may allow an attacker to read confidential information.

CVE-2018-10636 deltaww vulnerability CVSS: 9.3 13 Aug 2018, 21:47 UTC

CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabilities that could cause the software to crash due to lacking user input validation before copying data from project files onto the stack. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.

CVE-2018-10598 deltaww vulnerability CVSS: 5.8 13 Aug 2018, 21:47 UTC

CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validation for processing project files. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.

CVE-2018-10594 deltaww vulnerability CVSS: 7.5 26 Jun 2018, 20:29 UTC

Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.

CVE-2018-10623 deltaww vulnerability CVSS: 7.5 18 Jun 2018, 19:29 UTC

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buffer where the position can be determined by a value read from a .dpa file. This may cause improper restriction of operations within the bounds of the memory buffer, allow remote code execution, alter the intended control flow, allow reading of sensitive information, or cause the application to crash.

CVE-2018-10621 deltaww vulnerability CVSS: 7.5 18 Jun 2018, 19:29 UTC

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow remote code execution or cause the application to crash.

CVE-2018-10617 deltaww vulnerability CVSS: 7.5 18 Jun 2018, 19:29 UTC

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow remote code execution or cause the application to crash.

CVE-2018-8871 deltaww vulnerability CVSS: 7.5 25 May 2018, 16:29 UTC

In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, which may allow remote code execution.

CVE-2018-7509 deltaww vulnerability CVSS: 6.8 04 May 2018, 19:29 UTC

WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of the intended buffer space, which could cause memory corruption or may allow remote code execution.

CVE-2018-7507 deltaww vulnerability CVSS: 6.8 04 May 2018, 19:29 UTC

WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

CVE-2018-7494 deltaww vulnerability CVSS: 6.8 04 May 2018, 19:29 UTC

WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

CVE-2018-8839 deltaww vulnerability CVSS: 4.6 30 Apr 2018, 15:29 UTC

Delta PMSoft versions 2.10 and prior have multiple stack-based buffer overflow vulnerabilities where a .ppm file can introduce a value larger than is readable by PMSoft's fixed-length stack buffer. This can cause the buffer to be overwritten, which may allow arbitrary code execution or cause the application to crash. CVSS v3 base score: 7.1; CVSS vector string: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H. Delta Electronics recommends affected users update to at least PMSoft v2.11, which was made available as of March 22, 2018, or the latest available version.

CVE-2018-5476 deltaww vulnerability CVSS: 6.8 15 Mar 2018, 23:29 UTC

A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.00.01 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dop or .dpb files may allow an attacker to remotely execute arbitrary code.

CVE-2017-16751 deltaww vulnerability CVSS: 6.8 15 Mar 2018, 23:29 UTC

A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dpb files may allow an attacker to remotely execute arbitrary code.

CVE-2017-16749 deltaww vulnerability CVSS: 6.8 15 Mar 2018, 23:29 UTC

A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files could exploit a use-after-free vulnerability.

CVE-2017-16747 deltaww vulnerability CVSS: 6.8 15 Mar 2018, 23:29 UTC

An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

CVE-2017-16745 deltaww vulnerability CVSS: 6.8 15 Mar 2018, 23:29 UTC

A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. An access of resource using incompatible type ('type confusion') vulnerability may allow an attacker to execute remote code when processing specially crafted .dpb files.