CVE-2025-15359

9.1

Delta Electronics · DVP-12SE11T

Delta Electronics DVP-12SE11T devices contain an out-of-bounds memory write vulnerability that could allow unauthenticated remote attackers to cause a crash or execute arbitrary code.

Executive summary

Delta Electronics DVP-12SE11T devices are susceptible to an out-of-bounds memory write vulnerability, which may lead to service disruption or unauthorized code execution.

Vulnerability

This is an out-of-bounds memory write vulnerability that can be triggered by an unauthenticated remote attacker. The flaw allows for potential memory corruption, impacting system stability and integrity.

Business impact

Exploitation of this vulnerability poses a significant risk to industrial control environments, as the DVP-12SE11T is typically deployed in critical infrastructure. Successful execution could result in denial of service (system crash) or unauthorized control over the device. The CVSS score of 9.1 reflects the high potential for operational disruption.

Remediation

Immediate Action: Update the device firmware to version 2.16 or later immediately. The firmware update is the primary and only effective remediation for this vulnerability.

Proactive Monitoring: Monitor network traffic for anomalous packets directed at the device and check system logs for unexpected reboots or service failures.

Compensating Controls: Implement strict network segmentation to isolate the affected industrial hardware from untrusted networks, ensuring that only authorized traffic can reach the device.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of the hardware involved, organizations should prioritize firmware updates on all affected DVP-12SE11T units. Ensure all maintenance windows are used to apply version 2.16 to mitigate the risk of remote compromise.

More Delta Electronics CVEs