CVE-2025-15359
9.1Delta Electronics · DVP-12SE11T
Delta Electronics DVP-12SE11T devices contain an out-of-bounds memory write vulnerability that could allow unauthenticated remote attackers to cause a crash or execute arbitrary code.
Executive summary
Delta Electronics DVP-12SE11T devices are susceptible to an out-of-bounds memory write vulnerability, which may lead to service disruption or unauthorized code execution.
Vulnerability
This is an out-of-bounds memory write vulnerability that can be triggered by an unauthenticated remote attacker. The flaw allows for potential memory corruption, impacting system stability and integrity.
Business impact
Exploitation of this vulnerability poses a significant risk to industrial control environments, as the DVP-12SE11T is typically deployed in critical infrastructure. Successful execution could result in denial of service (system crash) or unauthorized control over the device. The CVSS score of 9.1 reflects the high potential for operational disruption.
Remediation
Immediate Action: Update the device firmware to version 2.16 or later immediately. The firmware update is the primary and only effective remediation for this vulnerability.
Proactive Monitoring: Monitor network traffic for anomalous packets directed at the device and check system logs for unexpected reboots or service failures.
Compensating Controls: Implement strict network segmentation to isolate the affected industrial hardware from untrusted networks, ensuring that only authorized traffic can reach the device.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of the hardware involved, organizations should prioritize firmware updates on all affected DVP-12SE11T units. Ensure all maintenance windows are used to apply version 2.16 to mitigate the risk of remote compromise.