Dopsoft
Vendor:
First CVE: Jun 30, 2020 · Active for 6 years
25
Total CVEs
More Total CVEs than 96% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
4.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Dopsoft over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2020
6 years ago
Most Recent CVE
Feb 29, 2024
880 days ago
CVE Severity & Scoring
Dopsoft25 CVEs
96%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local24 (96.0%)
Network1 (4.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (4.0%)
Unknown0 (0.0%)
Required24 (96.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None25 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38406HIGH Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bound | Sep 17, 2021 | 7.8 | 92 | YES | NO |
CVE-2021-38402HIGH Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer ov | Sep 17, 2021 | 7.8 | 27 | NO | NO |
CVE-2021-33019HIGH A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow | Aug 30, 2021 | 7.8 | 26 | NO | NO |
CVE-2020-27277HIGH Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code. | Jan 11, 2021 | 7.8 | 25 | NO | NO |
CVE-2023-43824HIGH A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated attacker | Jan 18, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-43823HIGH A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated attacker ca | Jan 18, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-43821HIGH A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated at | Jan 18, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-43819HIGH A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attack | Jan 18, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-43818HIGH A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a sp | Jan 18, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-0124HIGH Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute arbitrary code when a malformed | Feb 3, 2023 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
1 CVE
4.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Dopsoft
Top CWEs
Versions
No cataloged versions.