AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Delta Electronics
DE
Platform

Delta Electronics

IPC systems, VFDs, DIAView SCADA, and DVP/AS-series PLCs for comprehensive industrial automation solutions.

https://www.deltaww.com →
225
Total CVEs
0
Resources
62
CRIT
137
HIGH
21
MED
4
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
21 / 225
CVE-2023-5459MEDIUM

A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. VDB-241582 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Oct 9, 2023
6.5
CVE-2023-34316MEDIUM

​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.

Jul 10, 2023
6.5
CVE-2023-1137MEDIUM

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.

Mar 27, 2023
6.5
CVE-2018-14824MEDIUM

Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be executed when processing project files, which may allow an attacker to read confidential information.

Sep 27, 2018
6.5
CVE-2023-43816MEDIUM

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

Jan 18, 2024
6.3
CVE-2022-33005MEDIUM

A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1.08.00 allows attackers to execute arbitrary web scripts via a crafted payload injected into the Name text field.

Jun 27, 2022
6.1
CVE-2021-44768MEDIUM

Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.

Mar 25, 2022
6.1
CVE-2021-38424MEDIUM

The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

Nov 3, 2021
5.9
CVE-2025-57704MEDIUM

Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.

Aug 26, 2025
5.5
CVE-2022-2759MEDIUM

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

Aug 31, 2022
5.5
CVE-2021-38488MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-38428MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-38411MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-38407MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-38403MEDIUM

Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.

Nov 3, 2021
5.5
CVE-2021-33003MEDIUM

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

Aug 30, 2021
5.5
CVE-2021-27455MEDIUM

Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.

Jul 2, 2021
5.5
CVE-2019-10992MEDIUM

Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files.

Jul 24, 2019
5.5
CVE-2022-42141MEDIUM

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.

Dec 14, 2022
5.4
CVE-2021-32991MEDIUM

Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.

Aug 30, 2021
4.3
CVE-2025-59301MEDIUM

Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.

Dec 22, 2025
4.0
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2023-5459MEDIUM
6.5
A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. Th…Oct 9, 2023›
CVE-2023-34316MEDIUM
6.5
​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1…Jul 10, 2023›
CVE-2023-1137MEDIUM
6.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which …Mar 27, 2023›
CVE-2018-14824MEDIUM
6.5
Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulner…Sep 27, 2018›
CVE-2023-43816MEDIUM
6.3
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft vers…Jan 18, 2024›
CVE-2022-33005MEDIUM
6.1
A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Elect…Jun 27, 2022›
CVE-2021-44768MEDIUM
6.1
Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while …Mar 25, 2022›
CVE-2021-38424MEDIUM
5.9
The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attack…Nov 3, 2021›
CVE-2025-57704MEDIUM
5.5
Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Proce…Aug 26, 2025›
CVE-2022-2759MEDIUM
5.5
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by imp…Aug 31, 2022›
CVE-2021-38488MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-38428MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-38411MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-38407MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-38403MEDIUM
5.5
Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because a…Nov 3, 2021›
CVE-2021-33003MEDIUM
5.5
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in …Aug 30, 2021›
CVE-2021-27455MEDIUM
5.5
Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while…Jul 2, 2021›
CVE-2019-10992MEDIUM
5.5
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vuln…Jul 24, 2019›
CVE-2022-42141MEDIUM
5.4
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter…Dec 14, 2022›
CVE-2021-32991MEDIUM
4.3
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, wh…Aug 30, 2021›
CVE-2025-59301MEDIUM
4.0
Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denia…Dec 22, 2025›