CVE-2021-38406 is a critical out-of-bounds write vulnerability affecting Delta Electronic DOPSoft 2 (versions 2.00.07 and prior) due to improper validation of user-supplied project file data. This flaw carries a CVSS score of 7.8 (High) and could allow an unauthenticated attacker, through user interaction, to achieve arbitrary code execution with high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.00, <= 2.00.07CPE matchmatch criteria | cpe:2.3:a:deltaww:dopsoft:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.