These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Delta Electronics DIAEnergie versions up to and including v1.10.01.008 contain an authenticated SQL injection vulnerability in the Handler_CFG.ashx script. An attacker with valid credentials can exploit this flaw to inject malicious SQL commands, potentially causing operational delays in the targeted industrial control system. The vulnerability carries a HIGH severity CVSS 3.1 score of 8.8, reflecting sig [truncated]
Delta Electronics DTN Soft versions 2.0.1 and prior contain a deserialization of untrusted data vulnerability that can lead to remote code execution. The vulnerability was disclosed by CISA on August 29, 2024, with a CVSS 3.1 score of 7.8 (HIGH). The attack vector is local, requiring user interaction but no privileges, and can result in complete confidentiality, integrity, and availability compromise of t [truncated]
A stack-based buffer overflow vulnerability in Delta Electronics DIAScreen allows arbitrary code execution when processing maliciously crafted DPA files. The vulnerability, published 2024-08-06, carries a HIGH severity CVSS 7.8 score and requires local access with user interaction. Delta Electronics has released version 1.4.2 to address this issue.
Delta Electronics CNCSoft-G2 Version 2.1.0.10 and prior contains a heap-based buffer overflow vulnerability due to improper validation of user-supplied data length before copying to a fixed-length buffer. This vulnerability allows remote code execution in the context of the current process when a target visits a malicious page or opens a malicious file. The vulnerability was initially disclosed on July 9, [truncated]
Delta Electronics CNCSoft-G2 contains a heap-based buffer overflow vulnerability due to improper validation of user-supplied data length before copying to a fixed-length buffer. An attacker can exploit this by convincing a target to visit a malicious page or open a malicious file, resulting in arbitrary code execution in the context of the current process. The vulnerability affects CNCSoft-G2 version 2.0. [truncated]
Delta Electronics CNCSoft-G2 contains an out-of-bounds read vulnerability due to improper validation of user-supplied data. The flaw exists in version 2.0.0.5 and can be triggered when a target visits a malicious page or opens a malicious file, potentially allowing an attacker to execute arbitrary code within the context of the current process. CISA published the initial advisory on July 9, 2024, with an [truncated]
Delta Electronics CNCSoft-G2 contains a memory corruption vulnerability due to improper validation of user-supplied data. An attacker can exploit this flaw by convincing a target to visit a malicious web page or open a malicious file, resulting in arbitrary code execution within the context of the current process. The vulnerability affects CNCSoft-G2 version 2.0.0.5. CISA published the initial advisory on [truncated]
Delta Electronics CNCSoft-G2 contains a stack-based buffer overflow vulnerability due to improper validation of user-supplied data length before copying to a fixed-length buffer. An attacker can exploit this by convincing a target to visit a malicious page or open a malicious file, resulting in arbitrary code execution in the context of the current process. This vulnerability affects CNCSoft-G2 version 2. [truncated]
Delta Electronics DIAEnergie v1.10.00.005 contains a path traversal vulnerability due to insufficient input validation. An authenticated attacker with low privileges can exploit this flaw to write files outside the intended directory, with the additional risk of overwriting existing files on the target system. The vulnerability carries a HIGH severity CVSS 3.1 score of 8.8, reflecting significant confiden [truncated]
Delta Electronics DIAEnergie contains an authenticated SQL injection vulnerability in the GetDIACloudList endpoint that could allow complete system compromise. The vulnerability was disclosed by CISA on May 2, 2024, with a CVSS 3.1 score of 8.8 (HIGH). Affected versions include DIAEnergie v1.10.00.005. The vendor has released a patched version.
Delta Electronics DIAEnergie v1.10.00.005 contains an authenticated SQL injection vulnerability in the Handler_CFG.ashx script. An attacker with valid credentials can exploit this flaw to potentially compromise the underlying system. The vulnerability was disclosed by CISA on May 2, 2024, with a CVSS 3.1 score of 8.8 (High severity). A vendor fix is available in version v1.10.01.004.
Delta Electronics CNCSoft-G2 versions 2.1.0.27 and earlier contain a file parsing vulnerability that allows arbitrary code execution when a user opens a malicious file. The flaw stems from improper validation of user-supplied files, enabling attackers to execute code within the context of the current process. This vulnerability was initially disclosed on April 30, 2024, and subsequently updated on October [truncated]
Delta Electronics CNCSoft-G2 contains a stack-based buffer overflow vulnerability due to improper validation of user-supplied data length before copying to a fixed-length buffer. This local attack vector allows code execution in the context of the current process. The vulnerability was disclosed in April 2024 and updated in October 2025 to reflect modified affected products and mitigations. Affected versi [truncated]
CVE-2021-38406 affects Delta Electronics DOPSoft 2 and is included in CISA’s Known Exploited Vulnerabilities catalog, which indicates it is a vulnerability of active defensive concern. CISA’s supplied note says the impacted product is end-of-life and should be disconnected if still in use. For organizations that still rely on DOPSoft 2, the safest response is to treat this as an urgent remediation item an [truncated]
CVE-2016-5805 covers multiple heap-based buffer overflow conditions in Delta Electronics engineering software. According to the NVD record, WPLSoft versions prior to V2.42.11, ISPSoft versions prior to 3.02.11, and PMSoft versions prior to 2.10.10 are affected. The reported impact is that malicious files may trigger arbitrary code execution or a denial of service. NVD rates the issue HIGH with a CVSS 3.0 [truncated]
CVE-2016-5802 affects Delta Electronics WPLSoft, ISPSoft, and PMSoft versions prior to the vendor-fixed releases. NVD describes multiple out-of-bounds write conditions that may allow malicious files to be read and executed by the affected software. The published CVSS 3.0 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a local, user-interaction-dependent issue with high impact if triggered.