Executive brief
A vulnerability exists in the Delta Electronics DVP80ES300T programmable logic controller (PLC), which is a device used to automate industrial machinery and processes. An attacker could exploit this flaw to cause the device to crash or become unresponsive, potentially halting manufacturing lines or critical infrastructure operations. This issue can be triggered remotely over the network without requiring any user interaction or special access privileges.
Technical details
The Delta Electronics DVP80ES300T PLC (versions 1.08 and prior) is vulnerable to an improper validation of array index (CWE-129). The flaw occurs when the device processes network-based inputs that are used as an index to an array without proper bounds checking. A remote, unauthenticated attacker can exploit this by sending a specially crafted packet to the device, leading to an out-of-bounds read or write. According to the CVSS metrics, the primary impact is a total loss of availability (Denial of Service), as the device may crash or enter an error state.
Affected products
- Delta Electronics DVP80ES300T <= 1.08
Timeline
- 2026-07-01: disclosed
- 2026-07-01: advisory