Impact
The DVP80ES3 device contains an Improper Resource Shutdown or Release flaw (CWE‑404). The firmware fails to release system resources such as memory, file descriptors, or handles correctly during shutdown, resulting in resource leakage and potentially impairing device operation. It is inferred that repeated triggering of the flaw could consume resources, leading to a denial of service or degraded performance.
Affected Systems
DeltaWw’s DVP80ES3 units running firmware versions older than v01.08.10 are affected. All other firmware releases at the time of this advisory are considered secure.
Risk and Exploitability
The CVSS score of 7.5 signifies high severity. EPSS information is not available and the flaw is not listed in CISA KEV, indicating no current known exploitation on the internet. Based on the description, it is inferred that the attack requires local or authenticated access to the device to induce repeated shutdown conditions. The risk is significant for environments where the device is integral to operational workflows and may expose critical services to interruption.
OpenCVE Enrichment