Executive brief
Delta Electronics DVP12SE programmable logic controllers (PLCs), which are used to automate industrial machinery and processes, contain a vulnerability in how they manage network connections. An attacker could exploit this to overwhelm the device's resources, potentially causing the controller to crash or become unresponsive. This could lead to a complete shutdown of industrial operations or loss of control over connected equipment.
Technical details
A resource allocation vulnerability (CWE-770) exists in the Modbus TCP service of Delta Electronics DVP12SE PLCs. The service fails to implement proper limits or throttling on incoming requests or connection resources. A remote, unauthenticated attacker can exploit this by sending a high volume of Modbus TCP traffic to exhaust device resources. Successful exploitation can lead to a denial-of-service (DoS) condition, impacting the availability and integrity of the industrial control process. The vulnerability is rated critical due to the lack of authentication required and the potential for total system impact.
Affected products
- Delta Electronics DVP12SE PLC All versions
Timeline
- 2026-06-30: advisory: Initial advisory published by Delta Electronics and NVD.