← Back to home
ICSA-21-350-02  ·  Published 2021-12-16  ·  View on CISA ICS-CERT ↗

Delta Electronics CNCSoft

CVSS 6.1 MEDIUM

Risk Summary

Successful exploitation of this vulnerability could allow information disclosure or an application crash.

CVEs (1)

Remediations

  • Delta Electronics recommends users upgrade to the latest available patch.
  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the Internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from the business network.
  • When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as its connected devices.

Affected Vendors

Delta Electronics

Affected Products (1)

Delta Electronics · CNCSoft <= 1.01.30

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more