ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-38406
Out-of-Bounds Write Code Execution in Delta Electronics DOPSoft 2 Project File Parsing

Delta Electronics DOPSoft 2 (version 2.00.07 and prior) fails to properly validate user-supplied data when parsing project files, resulting in multiple out-of-bounds write vulnerabilities (CWE-787). Because the flaw requires local access and user interaction, exploitation typically involves tricking an engineer or operator into opening a maliciously crafted DOPSoft project file. Successful exploitation lets the attacker execute code in the context of the current process, i.e., as the logged-in user of the workstation running DOPSoft, which in OT environments is typically an engineering workstation with access to the control network. Only users still running the end-of-life DOPSoft 2 branch are affected; owners of Delta HMI deployments who have not migrated off this older configuration tool are in scope. The flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-25 as part of a batch of 10 additions, confirming active exploitation in the wild, and it carries a very high EPSS score of 76.4% (100th percentile), though no public proof-of-concept is known and ransomware use is unknown.

Do: Inventory engineering, maintenance, and other control-network-connected workstations for DOPSoft 2 (version 2.00.07 or earlier); per CISA's required action, stop using or disconnect the end-of-life DOPSoft 2 and migrate to a currently supported DOPSoft release where configuration software is still needed (no fixed version is specified in the available data). Until remediated, do not open DOPSoft project files from untrusted sources (email, downloads, removable media) on stations that have access to control networks.

7.876% KEV
  • Delta Electronics DOPSoft 2 version 2.00.07 and prior
moderate~10,000-100,000 engineering workstations worldwide (rough estimate; no public install counts exist)
CVE-2016-5805
+1 in the same advisory: …5802
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10.

An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of arbitrary code or a denial of service.

NVD description · AI analysis pending
7.82%
  • delta electronics ispsoft
  • delta electronics pmsoft
  • delta electronics wplsoft