Vulnerabilities > Deltaww > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-08-30 CVE-2021-38391 Unspecified vulnerability in Deltaww Diaenergie 1.7.5
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior.
network
low complexity
deltaww
critical
9.8
2021-08-30 CVE-2021-38393 Unspecified vulnerability in Deltaww Diaenergie 1.7.5
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior.
network
low complexity
deltaww
critical
9.8
2021-05-16 CVE-2021-22668 Unspecified vulnerability in Deltaww Cncsoft Screeneditor
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.
network
low complexity
deltaww
critical
9.8
2021-04-27 CVE-2021-27480 Unspecified vulnerability in Deltaww Industrial Automation Commgr
Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute remote code.
network
low complexity
deltaww
critical
9.8
2019-06-19 CVE-2019-12899 Out-of-bounds Write vulnerability in Deltaww Devicenet Builder 2.04
Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem+0x00000000000005e3.
network
low complexity
deltaww CWE-787
critical
9.8
2019-06-19 CVE-2019-12898 Out-of-bounds Write vulnerability in Deltaww Devicenet Builder 2.04
Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000000017a45e.
network
low complexity
deltaww CWE-787
critical
9.8
2018-06-26 CVE-2018-10594 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Deltaww Commgr 1.08
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten.
network
low complexity
deltaww CWE-119
critical
9.8
2018-06-18 CVE-2018-10623 Out-of-bounds Read vulnerability in Deltaww Delta Industrial Automation Dopsoft
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buffer where the position can be determined by a value read from a .dpa file.
network
low complexity
deltaww CWE-125
critical
9.8
2018-06-18 CVE-2018-10621 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Deltaww Delta Industrial Automation Dopsoft
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten.
network
low complexity
deltaww CWE-119
critical
9.8
2018-06-18 CVE-2018-10617 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Deltaww Delta Industrial Automation Dopsoft
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten.
network
low complexity
deltaww CWE-119
critical
9.8