Executive brief
The Delta Electronics DVP80ES3, a programmable logic controller (PLC) used to automate industrial machinery, is vulnerable to a denial-of-service attack. An attacker could exploit this flaw to crash the device or make it unresponsive, potentially halting manufacturing processes or industrial operations. This could lead to significant operational downtime and require manual intervention to restore service.
Technical details
The Delta Electronics DVP80ES3 PLC contains a vulnerability classified as Improper Resource Shutdown or Release (CWE-404). The flaw exists in the way the device handles network connections or internal system resources, failing to properly close or release them after use. A remote, unauthenticated attacker can exploit this by sending a series of specially crafted requests over the network to exhaust available resources. Successful exploitation results in a denial-of-service (DoS) condition, impacting the availability of the controller. Users are advised to refer to Delta-PCSA-2026-00009 for specific firmware patching or mitigation guidance.
Affected products
- Delta Electronics DVP80ES3
Timeline
- 2026-07-01: advisory: Initial NVD publication