Junglewise Threat Intelligence

CVE-2021-38406: Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability

CVE-2021-38406 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-08-25

Vendors: Delta Electronics.

Executive brief

Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files. This vulnerability results in an out-of-bounds write, which an attacker could leverage to execute arbitrary code in the context of the current process.

Affected products

  • Delta Electronics DOPSoft 2 2.00.07 and prior

Timeline

  • 2021-09-17: disclosed: NVD Published Date
  • 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-25: advisory: Published date provided in advisory metadata