SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2021-38406

HIGH · CVSS 7.8 EPSS 77.89% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-09-17 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Its EPSS score suggests a 77.9% probability of exploitation in the next 30 days.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2022-08-25

Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE
CVE-2021-38406
Severity
HIGH
CVSS
7.8
EPSS
77.89%

Original NVD Description

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)