Delta Electronics Alerts
2670Warning Date
Severity Level
Warning Number
Target Sector
29 August, 2021
● Critical
2021-3437
Manufacturing
Description:
Delta Electronics has released security alerts to address several vulnerabilities in the following products:
- DOPSoft
- DOPSoft Version 4.00.11 and prior
- DIAEnergie
- DIAEnergie Version 1.7.5 and prior
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Buffer overflow
- SQL injection
- Cross-site request forgery (CSRF)
Best practice and Recommendations:
The CERT team encourages users to apply best practice:
- Minimizing network exposure for all control system devices and/or systems
- Locating control system networks and devices behind firewalls and isolating them from the enterprise/business network
- When remote access is required, use secure methods such as virtual private networks (VPNs)
- Contact Delta Electronics for further assistance