Delta Electronics COMMGR Insufficient Randomization Session ID Brute Force Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in Delta Electronics COMMGR versions 1 and 2 due to the use of insufficiently randomized values for generating session IDs. This flaw allows attackers to easily brute force session IDs, potentially leading to unauthorized access and execution of arbitrary code within the application. The vulnerability arises from the use of cryptographically weak pseudo-random number generators, which fail to provide adequate randomness for secure session management.

Impact

Exploitation of this vulnerability could enable remote access to the AS3000Simulator family within the COMMGR software, allowing for the execution of arbitrary code.

Remediation

Delta Electronics is actively working on a fix for COMMGR version 2. Users of COMMGR version 1, which has reached end of life, are advised to minimize network exposure for control system devices and software, use secure remote access methods like VPNs, and isolate control system networks from business networks. Additional guidance is available on the CISA website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.7
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.