Delta Electronics DVP12SE PLC
Delta Electronics DVP12SE PLC (all versions) contains critical vulnerabilities in authentication and access control (CWE-306, CWE-770) that allow unauthenticated remote attackers to issue commands, modify operational values, interfere with control logic, and alter device behavior. The PLC lacks authentication enforcement on network interfaces, permitting an attacker on the network to remotely execute arbitrary commands without credentials. Delta Electronics is developing a firmware fix but has not yet released a patched version. In the interim, the vendor recommends enabling IP filtering, implementing PLC password protection, and deploying network isolation with firewall protection.
- Network access to the DVP12SE PLC (TCP/UDP ports typically used for Delta PLC communication, such as port 502 for Modbus or port 44818 for EtherCAT)
- No authentication or valid credentials required
- PLC must be network-reachable from the attacker's position
Patching may require device reboot — plan for process interruption
/api/v1/advisories/4c3fd73a-55ce-4f6c-b755-42d3fbd32c8fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.