Delta Electronics DVP-12SE11T Authentication Bypass via Partial Password Disclosure Vulnerability
Vulnerability
An authentication bypass vulnerability has been identified in the Delta Electronics DVP-12SE11T product, specifically in firmware versions prior to 2.16. This vulnerability arises from partial password disclosure, which can be exploited to bypass authentication mechanisms.
Impact
Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access or actions within the application or system.
Remediation
Users are advised to upgrade the firmware to version 2.16 or later. For additional security, implement robust network-level countermeasures, utilize the product's IP whitelisting feature to restrict Modbus/TCP access to trusted client IP addresses, and place the product within a highly segregated network zone, using industrial firewalls to monitor Modbus/TCP traffic.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
