QID 591213

QID 591213: Delta Electronics DOPSoft Unauthorized Information Disclosure Vulnerability (ICSA-22-244-01)

This updated advisory is a follow up to the original advisory titled ICSA 22-244-01 Delta Electronics DOPSoft that was published September 01 2022

Two out of bounds read conditions may occur due to the affected product not properly sanitizing input while processing specific project files which may allow unauthorized information disclosure

The following versions of DOPSoft a software supporting the DOP 100 series HMI screens are affected
DOPSoft All versions

QID Detection Logic(Authentication)
This checks for vulnerable version of DOPSoft

NA

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-244-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591213

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-244-01 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-244-01