PatchSiren cyber security CVE debrief
CVE-2025-22883 Delta Electronics CVE debrief
CVE-2025-22883 affects Delta Electronics ISPSoft versions 3.19 and prior. According to the CISA CSAF advisory, the issue is an out-of-bounds write that can allow arbitrary code execution when ISPSoft parses DVP files. Delta recommends updating to ISPSoft v3.21 or later. This is a high-severity issue (CVSS 7.8) and is especially important for environments where engineering workstations routinely open DVP files from external or untrusted sources.
- Vendor
- Delta Electronics
- Product
- ISPSoft
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-29
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-29
- Advisory updated
- 2025-05-06
Who should care
OT/ICS teams using Delta Electronics ISPSoft, engineering workstation owners, automation engineers, plant security teams, and vulnerability management teams responsible for Windows-based engineering tools used to open DVP project files.
Technical summary
The advisory describes a memory corruption condition in ISPSoft's DVP file parsing logic. A crafted DVP file can trigger an out-of-bounds write, which may lead to arbitrary code execution. The supplied CVSS vector indicates local attack conditions with required user interaction (AV:L/UI:R), no privileges needed, and potential high impact to confidentiality, integrity, and availability.
Defensive priority
High for any organization that uses ISPSoft in operational or engineering workflows, particularly where DVP files may be transferred from external parties or shared across trust boundaries. Patch prioritization should be elevated for exposed engineering workstations and shared file-handling environments.
Recommended defensive actions
- Update Delta Electronics ISPSoft to version 3.21 or later, as recommended in the vendor advisory.
- Inventory engineering workstations and confirm which systems have ISPSoft version 3.19 or earlier installed.
- Treat DVP files from outside trusted workflows as untrusted input and review file-handling procedures accordingly.
- Reduce exposure of engineering workstations by following CISA ICS recommended practices, including segmentation and limiting unnecessary software on critical systems.
- Use application control, least privilege, and workstation hardening measures appropriate for ICS engineering environments.
- Monitor vendor and CISA advisories for any follow-up guidance or corrections related to CVE-2025-22883.
Evidence notes
Primary evidence comes from the CISA CSAF advisory for ICSA-25-119-02, which identifies Delta Electronics ISPSoft versions 3.19 and prior as affected by an out-of-bounds write during DVP parsing and states that updating to v3.21 or later is the vendor recommendation. The CVSS 3.1 vector and score are included in the supplied source item metadata. The advisory was initially published on 2025-04-29 and revised on 2025-05-06 for typo fixes.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-22883 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-22883
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-22883 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-22883
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-119-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-119-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.