Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-32223 Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Fixes

Solution

Download and update to DIAScreen v1.6.1 or later


Workaround

No workaround given by the vendor.

History

Wed, 08 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Deltaww
Deltaww diascreen
CPEs cpe:2.3:a:deltaww:diascreen:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diascreen
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 03 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Oct 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Delta Electronics
Delta Electronics diascreen
Vendors & Products Delta Electronics
Delta Electronics diascreen

Fri, 03 Oct 2025 02:45:00 +0000

Type Values Removed Values Added
Description Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Title File Parsing Out-Of-Bounds Write Vulnerability in DIAScreen
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2025-10-07T01:03:20.129Z

Reserved: 2025-09-12T01:31:46.228Z

Link: CVE-2025-59297

cve-icon Vulnrichment

Updated: 2025-10-03T15:50:41.576Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-03T03:15:34.787

Modified: 2025-10-08T16:07:00.640

Link: CVE-2025-59297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-03T08:22:27Z

Weaknesses