CVE-2026-12818
Deferred Deferred - Pending Action

Resource Exhaustion in Delta DVP12SE PLC Modbus TCP

Vulnerability report for CVE-2026-12818, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-30

Last updated on: 2026-06-30

Assigner: Deltaww

Description

Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-30
Last Modified
2026-06-30
Generated
2026-07-20
AI Q&A
2026-06-30
EPSS Evaluated
2026-07-19
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
delta_electronics dvp12se *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12818 is a critical vulnerability in Delta Electronics DVP12SE PLCs involving a resource allocation flaw without limits or throttling, classified as CWE-770.

This means the Modbus TCP service on these devices can be exploited by an attacker to consume excessive resources, potentially causing denial-of-service conditions or other severe impacts.

Detection Guidance

The vulnerability in Delta Electronics DVP12SE PLCs involves resource allocation without limits or throttling in the Modbus TCP service, which could be detected by monitoring unusual or excessive resource consumption related to Modbus TCP traffic.

While specific commands are not provided in the available resources, general detection methods could include network traffic analysis to identify abnormal Modbus TCP connection patterns or resource usage spikes on the PLC devices.

Recommended mitigation steps include enabling IP filtering to restrict access to trusted devices, setting PLC password protection, and isolating the network with firewall protection, which can also help in detecting unauthorized access attempts.

Impact Analysis

The vulnerability can allow attackers to exploit excessive resource consumption on the affected PLCs, which may lead to denial-of-service conditions.

This could disrupt the normal operation of the PLCs, potentially causing system downtime or failure in industrial control processes.

Compliance Impact

The vulnerability in Delta Electronics DVP12SE PLCs allows for resource exhaustion leading to potential denial-of-service conditions. Such disruptions can impact the availability and reliability of systems processing sensitive data, which is a critical aspect of compliance with standards like GDPR and HIPAA that require ensuring data availability and integrity.

Failure to mitigate this vulnerability could result in unauthorized denial of service, potentially affecting the confidentiality, integrity, and availability of protected data, thereby risking non-compliance with regulatory requirements.

Recommended mitigations such as IP filtering, password protection, network isolation, and secure VPN access help maintain compliance by protecting against unauthorized access and ensuring system availability.

Mitigation Strategies

To mitigate the CVE-2026-12818 vulnerability in Delta Electronics DVP12SE PLCs, the following immediate steps are recommended:

  • Enable the IP Filter feature to restrict access to trusted devices only.
  • Set up PLC password protection to prevent unauthorized changes.
  • Implement network isolation using firewall protection.
  • Allow remote access only through a secure VPN.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12818. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart