VYPR

Vendor CVEs

Delta Electronics

All CVEs

276 total · sorted by risk
  • CVE-2020-27277HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2020-27275HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.03

    Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2020-16227HigAug 7, 2020
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by processing a specially crafted project file not validated when the data is entered by a user. Successful exploitation of this vulnerability may allow an attacker to read/modify…

  • CVE-2020-16225HigAug 7, 2020
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash…

  • CVE-2020-16223HigAug 7, 2020
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash…

  • CVE-2020-16221HigAug 7, 2020
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics TPEditor Versions 1.97 and prior. A stack-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash…

  • CVE-2020-16219HigAug 7, 2020
    risk 0.51cvss 7.8epss 0.03

    Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by processing specially crafted project files. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the…

  • CVE-2019-13544HigSep 11, 2019
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics TPEditor, Versions 1.94 and prior. Multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files, which may allow remote code execution.

  • CVE-2019-13540HigSep 11, 2019
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics TPEditor, Versions 1.94 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-13536HigSep 11, 2019
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-10982HigJul 24, 2019
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input…

  • CVE-2018-17929HigOct 11, 2018
    risk 0.51cvss 7.8epss 0.02

    In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files lacking user input validation before copying data from project files onto the stack and…

  • CVE-2018-17927HigOct 11, 2018
    risk 0.51cvss 7.8epss 0.02

    In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer…

  • CVE-2018-14800HigOct 3, 2018
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application to read past the boundary allocated to a stack object, which could allow execution of code under the context of the application.

  • CVE-2018-8839HigApr 30, 2018
    risk 0.51cvss 7.8epss 0.00

    Delta PMSoft versions 2.10 and prior have multiple stack-based buffer overflow vulnerabilities where a .ppm file can introduce a value larger than is readable by PMSoft's fixed-length stack buffer. This can cause the buffer to be overwritten, which may allow arbitrary code…

  • CVE-2018-5476HigMar 15, 2018
    risk 0.51cvss 7.8epss 0.02

    A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.00.01 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dop or .dpb files may allow an attacker to remotely execute…

  • CVE-2017-16751HigMar 15, 2018
    risk 0.51cvss 7.8epss 0.02

    A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dpb files may allow an attacker to remotely execute…

  • CVE-2017-16749HigMar 15, 2018
    risk 0.51cvss 7.8epss 0.01

    A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files could exploit a use-after-free vulnerability.

  • CVE-2017-16747HigMar 15, 2018
    risk 0.51cvss 7.8epss 0.01

    An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

  • CVE-2017-16745HigMar 15, 2018
    risk 0.51cvss 7.8epss 0.01

    A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. An access of resource using incompatible type ('type confusion') vulnerability may allow an attacker to execute remote code when processing…

  • CVE-2016-5805HigFeb 13, 2017
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of…

  • CVE-2016-5802HigFeb 13, 2017
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to 2.10.10. Multiple instances of out-of-bounds write conditions may allow malicious files to be read and executed by the affected…

  • CVE-2021-44544HigDec 22, 2021
    risk 0.50cvss 7.5epss 0.09

    DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”.

  • CVE-2026-3631HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.

  • CVE-2024-4549HigMay 6, 2024
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

  • CVE-2023-43817HigJan 18, 2024
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code…

  • CVE-2023-47279HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.

  • CVE-2023-1142HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.01

    In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.

  • CVE-2023-1138HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.

  • CVE-2022-41776HigOct 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the…

  • CVE-2022-41629HigOct 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify…

  • CVE-2021-44471HigDec 22, 2021
    risk 0.49cvss 7.5epss 0.01

    DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.

  • CVE-2021-23228HigDec 22, 2021
    risk 0.49cvss 7.5epss 0.01

    DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.

  • CVE-2025-58320HigSep 11, 2025
    risk 0.48cvss 7.3epss 0.14

    Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

  • CVE-2025-47728HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-47727HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-47726HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-47725HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-47724HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2022-4616HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.05

    The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions.

  • CVE-2022-42140HigDec 14, 2022
    risk 0.47cvss 7.2epss 0.02

    Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

  • CVE-2023-43815HigJan 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to…

  • CVE-2023-1134HigMar 27, 2023
    risk 0.46cvss 7.1epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.

  • CVE-2022-0988HigMar 25, 2022
    risk 0.46cvss 7.1epss 0.01

    Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.

  • CVE-2021-31558MedDec 22, 2021
    risk 0.43cvss 6.5epss 0.11

    DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.

  • CVE-2023-5459MedOct 9, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and…

  • CVE-2023-34316MedJul 10, 2023
    risk 0.42cvss 6.5epss 0.01

    ​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.

  • CVE-2023-1137MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.

  • CVE-2018-14824MedSep 27, 2018
    risk 0.42cvss 6.5epss 0.02

    Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be executed when processing project files, which may allow an attacker to read confidential information.

  • CVE-2023-43816MedJan 18, 2024
    risk 0.41cvss 6.3epss 0.00

    A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve…

Page 5 of 6