Dopsoft

Vendor:

First CVE: Jun 30, 2020 · Active for 6 years

25
Total CVEs
More Total CVEs than 96% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
4.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Dopsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2020
6 years ago
Most Recent CVE
Feb 29, 2024
880 days ago

CVE Severity & Scoring

Dopsoft25 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local24 (96.0%)
Network1 (4.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (4.0%)
Unknown0 (0.0%)
Required24 (96.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None25 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bound
Sep 17, 20217.892YESNO
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer ov
Sep 17, 20217.827NONO
A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow
Aug 30, 20217.826NONO
Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.
Jan 11, 20217.825NONO
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated attacker
Jan 18, 20247.824NONO
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated attacker ca
Jan 18, 20247.824NONO
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated at
Jan 18, 20247.824NONO
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attack
Jan 18, 20247.824NONO
A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a sp
Jan 18, 20247.824NONO
Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute arbitrary code when a malformed
Feb 3, 20237.824NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
1 CVE
4.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Dopsoft

Top CWEs

Versions

No cataloged versions.