Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.
Conclusion & alert: CVE-2021-38406 is rated Critical Active Threat (85.6/100): CVSS High severity, with high exploitation likelihood (EPSS 62.13%, 98th percentile).Core evidence: CISA KEV confirms active exploitation (added 2022-08-25) affecting Delta Electronics / DOPSoft 2. a weakness (CWE-787) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Exploit prediction scoring system (EPSS) score for CVE-2021-38406
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).