CVE-2025-3495: COMMGR - Insufficient Randomization Authentication Bypass
Published Apr 16, 2025
·Updated
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.
Affected Software
3 affected components
Delta Electronics COMMGR
: Delta Electronics COMMGR (Version 1)
: Delta Electronics COMMGR (Version 2)
Remediation
Information
Users are recommended to download and upgrade to COMMGR v2.10.0 or later.
Event History
Apr 16, 2025
CVE Published
via MITRE·03:10 AM
Data Sourced
via MITRE·03:10 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3495?
CVE-2025-3495 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2025-3495?
To fix CVE-2025-3495, update to the latest patched version of Delta Electronics COMMGR that addresses session ID generation.
3
What systems are affected by CVE-2025-3495?
CVE-2025-3495 affects versions 1 and 2 of Delta Electronics COMMGR.
4
What type of vulnerability is CVE-2025-3495?
CVE-2025-3495 is an authentication bypass vulnerability due to insufficient randomization of session IDs.
5
Can CVE-2025-3495 lead to data compromise?
Yes, CVE-2025-3495 can lead to data compromise as attackers may execute arbitrary code by brute-forcing session IDs.