AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-38406

HIGH · CVSS 7.8 EPSS 77.89% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-09-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2022-08-25

Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE
CVE-2021-38406
Severity
HIGH
CVSS
7.8
EPSS
77.89%

Original NVD Description

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.