Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

Project Subscriptions

Vendors Products
Deltaww Subscribe
Ispsoft Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12684 Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.
Fixes

Solution

Download and update to: v3.21 or later


Workaround

No workaround given by the vendor.

History

Mon, 25 Aug 2025 03:30:00 +0000


Mon, 25 Aug 2025 03:15:00 +0000


Fri, 16 May 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Deltaww
Deltaww ispsoft
Weaknesses CWE-787
CPEs cpe:2.3:a:deltaww:ispsoft:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww ispsoft

Wed, 30 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 07:45:00 +0000

Type Values Removed Values Added
Description Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.
Title ISPSoft File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2025-08-25T02:57:56.078Z

Reserved: 2025-01-09T03:48:26.774Z

Link: CVE-2025-22884

cve-icon Vulnrichment

Updated: 2025-04-30T13:04:27.647Z

cve-icon NVD

Status : Modified

Published: 2025-04-30T08:15:31.760

Modified: 2025-08-25T03:15:37.003

Link: CVE-2025-22884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses