Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-32219 Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Fixes

Solution

Download and update to DIAScreen v1.6.1 or later


Workaround

No workaround given by the vendor.

History

Wed, 08 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Deltaww
Deltaww diascreen
CPEs cpe:2.3:a:deltaww:diascreen:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diascreen
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 03 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Oct 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Delta Electronics
Delta Electronics diascreen
Vendors & Products Delta Electronics
Delta Electronics diascreen

Fri, 03 Oct 2025 02:45:00 +0000

Type Values Removed Values Added
Description Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.
Title File Parsing Out-Of-Bounds Write Vulnerability in DIAScreen
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2025-10-07T01:04:20.201Z

Reserved: 2025-09-12T01:31:46.229Z

Link: CVE-2025-59300

cve-icon Vulnrichment

Updated: 2025-10-03T15:53:53.388Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-03T03:15:35.897

Modified: 2025-10-08T16:06:43.490

Link: CVE-2025-59300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-03T08:22:28Z

Weaknesses