VYPR
Unrated severityNVD Advisory· Published Jan 18, 2024· Updated Jun 16, 2025

Delta Electronics Delta Industrial Automation DOPSoft DPS File wLogTitlesTimeLen Buffer Overflow Remote Code Execution

CVE-2023-43822

Description

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack buffer overflow in Delta Electronics DOPSoft when parsing DPS file wLogTitlesTimeLen field allows remote code execution via crafted file.

Vulnerability

A stack-based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. The affected product is end-of-life, and all versions are vulnerable. The vulnerability is triggered during the parsing of a specially crafted DPS file [1].

Exploitation

An unauthenticated remote attacker can exploit this vulnerability by enticing a user to open a malicious DPS file. No special privileges or network access beyond delivering the file are required. The attacker crafts a DPS file with an oversized wLogTitlesTimeLen field, and upon the user opening the file in DOPSoft, the stack buffer overflow occurs [1].

Impact

Successful exploitation allows the attacker to achieve remote code execution in the context of the DOPSoft process. This can lead to full compromise of the affected system, including potential data exfiltration, installation of malware, or further lateral movement [1].

Mitigation

The affected product is end-of-life, and no patches are available. Users are advised to discontinue use of DOPSoft and migrate to supported alternatives. No workarounds are provided in the available references [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.