ID

VAR-202412-2326


CVE

CVE-2024-12677


TITLE

Delta Electronics DTM Soft BIN File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability

Trust: 0.7

sources: ZDI: ZDI-24-1721

DESCRIPTION

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of BIN files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. Delta Electronics DTM is a series of temperature controllers manufactured by Delta Electronics, a Chinese company

Trust: 2.07

sources: NVD: CVE-2024-12677 // ZDI: ZDI-24-1721 // CNVD: CNVD-2025-26914

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-26914

AFFECTED PRODUCTS

vendor:deltamodel:dtm softscope: - version: -

Trust: 0.7

vendor:deltamodel:electronics dtm softscope:lteversion:<=1.30

Trust: 0.6

sources: ZDI: ZDI-24-1721 // CNVD: CNVD-2025-26914

CVSS

SEVERITY

CVSSV2

CVSSV3

ics-cert@hq.dhs.gov: CVE-2024-12677
value: HIGH

Trust: 1.0

ZDI: CVE-2024-12677
value: HIGH

Trust: 0.7

CNVD: CNVD-2025-26914
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-26914
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

ics-cert@hq.dhs.gov: CVE-2024-12677
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

ZDI: CVE-2024-12677
baseSeverity: HIGH
baseScore: 7.8
vectorString: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-24-1721 // CNVD: CNVD-2025-26914 // NVD: CVE-2024-12677

PROBLEMTYPE DATA

problemtype:CWE-502

Trust: 1.0

sources: NVD: CVE-2024-12677

PATCH

title:Delta Electronics has issued an update to correct this vulnerability.url:https://www.cisa.gov/news-events/ics-advisories/icsa-24-354-03

Trust: 0.7

title:Patch for Delta Electronics DTM code vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/749056

Trust: 0.6

sources: ZDI: ZDI-24-1721 // CNVD: CNVD-2025-26914

EXTERNAL IDS

db:NVDid:CVE-2024-12677

Trust: 2.3

db:ICS CERTid:ICSA-24-354-03

Trust: 1.6

db:ZDI_CANid:ZDI-CAN-22331

Trust: 0.7

db:ZDIid:ZDI-24-1721

Trust: 0.7

db:CNVDid:CNVD-2025-26914

Trust: 0.6

sources: ZDI: ZDI-24-1721 // CNVD: CNVD-2025-26914 // NVD: CVE-2024-12677

REFERENCES

url:https://www.cisa.gov/news-events/ics-advisories/icsa-24-354-03

Trust: 2.3

url:https://downloadcenter.deltaww.com/en-us/downloadcenter?v=1&q=dtm&sort_expr=cdate&sort_dir=desc

Trust: 1.0

sources: ZDI: ZDI-24-1721 // CNVD: CNVD-2025-26914 // NVD: CVE-2024-12677

CREDITS

kimiya

Trust: 0.7

sources: ZDI: ZDI-24-1721

SOURCES

db:ZDIid:ZDI-24-1721
db:CNVDid:CNVD-2025-26914
db:NVDid:CVE-2024-12677

LAST UPDATE DATE

2025-11-19T23:02:40.490000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-24-1721date:2024-12-20T00:00:00
db:CNVDid:CNVD-2025-26914date:2025-11-05T00:00:00
db:NVDid:CVE-2024-12677date:2024-12-20T17:15:07.757

SOURCES RELEASE DATE

db:ZDIid:ZDI-24-1721date:2024-12-20T00:00:00
db:CNVDid:CNVD-2025-26914date:2025-11-07T00:00:00
db:NVDid:CVE-2024-12677date:2024-12-20T17:15:07.757