Delta Electronics EIP Builder XML External Entity Processing Information Disclosure Vulnerability

Vulnerability

A file parsing vulnerability allowing XML external entity (XXE) processing has been identified in Delta Electronics EIP Builder version 1.11 and prior. This vulnerability could lead to unauthorized information disclosure.

Impact

Exploitation of this vulnerability could result in improper restriction of XML external entity references, allowing for potential information disclosure.

Remediation

Users are advised to download and update to version 1.12 or later. For version 1.12 or later, visit the Delta Download Center.

Added: Aug 26, 2025, 7:20 AM
Updated: Aug 26, 2025, 7:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
7.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.