CVE-2021-38406
KEVmoderateOut-of-Bounds Write Code Execution in Delta Electronics DOPSoft 2 Project File Parsing
CISA: Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability
Delta Electronics DOPSoft 2 (version 2.00.07 and prior) fails to properly validate user-supplied data when parsing project files, resulting in multiple out-of-bounds write vulnerabilities (CWE-787). Because the flaw requires local access and user interaction, exploitation typically involves tricking an engineer or operator into opening a maliciously crafted DOPSoft project file. Successful exploitation lets the attacker execute code in the context of the current process, i.e., as the logged-in user of the workstation running DOPSoft, which in OT environments is typically an engineering workstation with access to the control network. Only users still running the end-of-life DOPSoft 2 branch are affected; owners of Delta HMI deployments who have not migrated off this older configuration tool are in scope. The flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-25 as part of a batch of 10 additions, confirming active exploitation in the wild, and it carries a very high EPSS score of 76.4% (100th percentile), though no public proof-of-concept is known and ransomware use is unknown.
What to do: Inventory engineering, maintenance, and other control-network-connected workstations for DOPSoft 2 (version 2.00.07 or earlier); per CISA's required action, stop using or disconnect the end-of-life DOPSoft 2 and migrate to a currently supported DOPSoft release where configuration software is still needed (no fixed version is specified in the available data). Until remediated, do not open DOPSoft project files from untrusted sources (email, downloads, removable media) on stations that have access to control networks.
| Delta Electronics DOPSoft 2 | version 2.00.07 and prior |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.
- Affected
- Delta Electronics DOPSoft 2
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- deltaww
- Products
- dopsoft
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H