Delta Electronics Delta Industrial Automation Screen Editor
Delta Industrial Automation Screen Editor Version 2.00.23.00 and earlier contains multiple memory safety vulnerabilities (buffer overflow, use-after-free, type confusion) in file parsing that can be triggered by processing specially crafted project files. An attacker with local access who convinces a user to open a malicious file could crash the application or potentially execute arbitrary code. Delta Electronics has end-of-lifed this product and replaced it with DOPSoft Version 2. The vendor recommends restricting application use to trusted files only.
- Local access to engineering workstation running Screen Editor
- User interaction required (opening a malicious file)
- Screen Editor Version 2.00.23.00 or earlier installed
Patching may require device reboot — plan for process interruption
/api/v1/advisories/84c1e014-e8f3-47f8-bca9-f9af8b8fb58bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.