Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.

Project Subscriptions

Vendors Products
Deltaww Subscribe
Dopsoft Subscribe
Advisories

No advisories yet.

Fixes

Solution

DOPSoft 2 will not receive an update to mitigate these vulnerabilities because it is an end-of-life product. Delta Electronics recommends users to switch to the replacement software when available


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 10 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-08-25'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-10-21T23:25:32.113Z

Reserved: 2021-08-10T00:00:00.000Z

Link: CVE-2021-38406

cve-icon Vulnrichment

Updated: 2024-08-04T01:37:16.611Z

cve-icon NVD

Status : Analyzed

Published: 2021-09-17T19:15:08.710

Modified: 2025-10-30T15:54:29.457

Link: CVE-2021-38406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses