CVE-2023-5459

A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. VDB-241582 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://drive.google.com/drive/folders/1mUKkl_NPoUENpPUq-pdQQaEEGvKAaIFB Permissions Required
https://vuldb.com/?ctiid.241582 Permissions Required Third Party Advisory
https://vuldb.com/?id.241582 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:deltaww:dvp32es200r_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200r:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:deltaww:dvp32es200t_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200t:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:deltaww:dvp32es211t_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es211t:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:deltaww:dvp32es200rc_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200rc:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:deltaww:dvp32es200tc_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200tc:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:deltaww:dvp32es200re_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200re:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:deltaww:dvp32es200te_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200te:-:*:*:*:*:*:*:*

History

16 Oct 2023, 13:54

Type Values Removed Values Added
First Time Deltaww dvp32es211t Firmware
Deltaww dvp32es200rc
Deltaww dvp32es211t
Deltaww dvp32es200t
Deltaww dvp32es200r Firmware
Deltaww dvp32es200tc Firmware
Deltaww
Deltaww dvp32es200te
Deltaww dvp32es200re
Deltaww dvp32es200r
Deltaww dvp32es200tc
Deltaww dvp32es200te Firmware
Deltaww dvp32es200rc Firmware
Deltaww dvp32es200t Firmware
Deltaww dvp32es200re Firmware
References (MISC) https://vuldb.com/?ctiid.241582 - (MISC) https://vuldb.com/?ctiid.241582 - Permissions Required, Third Party Advisory
References (MISC) https://vuldb.com/?id.241582 - (MISC) https://vuldb.com/?id.241582 - Third Party Advisory
References (MISC) https://drive.google.com/drive/folders/1mUKkl_NPoUENpPUq-pdQQaEEGvKAaIFB - (MISC) https://drive.google.com/drive/folders/1mUKkl_NPoUENpPUq-pdQQaEEGvKAaIFB - Permissions Required
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:o:deltaww:dvp32es200rc_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:o:deltaww:dvp32es211t_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200rc:-:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200t:-:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200re:-:*:*:*:*:*:*:*
cpe:2.3:o:deltaww:dvp32es200tc_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:o:deltaww:dvp32es200t_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es211t:-:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200tc:-:*:*:*:*:*:*:*
cpe:2.3:o:deltaww:dvp32es200re_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:o:deltaww:dvp32es200te_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:o:deltaww:dvp32es200r_firmware:1.48:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200te:-:*:*:*:*:*:*:*
cpe:2.3:h:deltaww:dvp32es200r:-:*:*:*:*:*:*:*

09 Oct 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-09 19:15

Updated : 2024-04-11 01:23


NVD link : CVE-2023-5459

Mitre link : CVE-2023-5459

CVE.ORG link : CVE-2023-5459


JSON object : View

Products Affected

deltaww

  • dvp32es211t_firmware
  • dvp32es200t
  • dvp32es200te
  • dvp32es211t
  • dvp32es200t_firmware
  • dvp32es200re_firmware
  • dvp32es200r
  • dvp32es200te_firmware
  • dvp32es200rc_firmware
  • dvp32es200re
  • dvp32es200tc
  • dvp32es200rc
  • dvp32es200tc_firmware
  • dvp32es200r_firmware
CWE
CWE-404

Improper Resource Shutdown or Release