HIGH

CVE-2021-38406

Deltaww Dopsoft 2021-09-17 CVSS v3.1
CVSS
7.8
KEV

Description

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.

Summary dbcve.org

Delta Electronic DOPSoft 2 versions 2.00.07 and prior contain a file parsing vulnerability where user-supplied data in project files is not properly validated, leading to multiple out-of-bounds write conditions that can be exploited for arbitrary code execution in the context of the running process.

Mitigation

Restrict handling of untrusted DOPSoft project files; isolate the application from untrusted network sources; monitor vendor for security updates that address the parsing validation flaws.

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

76.43%
Probability of exploitation in next 30 days
99.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE