CVE-2026-3631
7.5Delta Electronics · COMMGR2
Delta Electronics COMMGR2 is susceptible to a buffer over-read vulnerability that can be triggered by an unauthenticated attacker to cause a denial of service.
Executive summary
A critical buffer over-read vulnerability in Delta Electronics COMMGR2 allows unauthenticated attackers to trigger a denial of service condition.
Vulnerability
The software contains an out-of-bounds read vulnerability (CWE-125) within its communication management components. An unauthenticated remote attacker can exploit this flaw to cause the application to crash, resulting in a denial of service.
Business impact
Successful exploitation of this vulnerability results in a denial of service, which can disrupt industrial communication processes and operational workflows. Given the CVSS score of 7.5, this high-severity flaw represents a significant risk to availability, particularly in environments where COMMGR2 is critical for system connectivity and data exchange.
Remediation
Immediate Action: Upgrade Delta Electronics COMMGR2 to version 2.11.1 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor system logs and network traffic for unusual patterns or frequent application restarts that may indicate attempted exploitation.
Compensating Controls: Deploy network-level access controls to restrict access to the COMMGR2 service to authorized IP addresses only, reducing the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this denial of service vulnerability necessitates prompt action to maintain operational integrity. Administrators should prioritize the deployment of the vendor-provided update to version 2.11.1 to eliminate the risk of service disruption.
More Delta Electronics CVEs
Sources
Originally found and disclosed by Tenable, per the CVE Program record.