Junglewise Threat Intelligence

CVE-2026-12577: Delta Electronics DVP80ES3 improperly implemented security check

CVE-2026-12577 · Severity: info · CVSS 8.7 · Published 2026-07-01

Technologies: Delta Electronics DVP80ES3. Vendors: Delta Electronics.

Executive brief

Delta Electronics DVP80ES3 series programmable logic controllers (PLCs) contain a security flaw in how they validate standard security checks. These devices are commonly used in industrial automation to control machinery and manufacturing processes. An attacker could exploit this weakness over the network to cause a denial-of-service, potentially halting industrial operations and impacting production availability.

Technical details

A vulnerability classified as CWE-358 (Improperly Implemented Security Check for Standard) exists in Delta Electronics DVP80ES3 firmware versions 1.08.10 and earlier. The flaw resides in the implementation of standard security validation mechanisms within the PLC. A remote, unauthenticated attacker can exploit this over a network (AV:N) without user interaction (UI:N). Successful exploitation primarily impacts availability (VA:H), potentially leading to a denial-of-service (DoS) of the controller. The vendor has addressed this in advisory Delta-PCSA-2026-00009.

Affected products

  • Delta Electronics DVP80ES3 0 through 1.08.10

Timeline

  • 2026-07-01: advisory
  • 2026-07-01: disclosed

References

Related threats