Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-12576

CVE-2026-12576: DVP80ES3 Information Disclosure Flaw

CVE-2026-12576 is an information disclosure vulnerability in DVP80ES3 caused by improper enforcement of message integrity during transmission. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-12576 Overview

CVE-2026-12576 affects the Delta Electronics DVP80ES3 programmable logic controller (PLC). The vulnerability stems from improper enforcement of message integrity during transmission in a communication channel [CWE-924]. Attackers can exploit this flaw over the network without authentication or user interaction.

The weakness allows adversaries to tamper with communications between the DVP80ES3 device and its clients. Successful exploitation results in a high-impact denial of service against the affected industrial control device. The vulnerability carries a network attack vector with low attack complexity, making it accessible to remote attackers.

Critical Impact

Remote unauthenticated attackers can disrupt DVP80ES3 PLC availability by exploiting missing message integrity checks in the communication channel.

Affected Products

  • Delta Electronics DVP80ES3 programmable logic controller
  • Refer to the Delta Electronics security advisory for version-specific details
  • No CPE identifiers were published in the National Vulnerability Database entry

Discovery Timeline

  • 2026-07-01 - CVE-2026-12576 published to the National Vulnerability Database
  • 2026-07-01 - Last updated in the National Vulnerability Database

Technical Details for CVE-2026-12576

Vulnerability Analysis

The DVP80ES3 fails to enforce message integrity for data transmitted across its communication channel. This weakness maps to [CWE-924], Improper Enforcement of Message Integrity During Transmission in a Communication Channel. The protocol used by the device does not verify that received messages remain unaltered between sender and receiver.

Attackers positioned to send crafted traffic to the device can inject or modify protocol messages. Because the device processes these messages as legitimate, the manipulation can trigger conditions that halt availability. The availability impact is rated high, while confidentiality and integrity of stored data are not directly affected according to the published CVSS vector.

At the time of publication, no public proof-of-concept exploit has been observed. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Root Cause

The root cause is the absence of a cryptographic or checksum-based integrity mechanism on the DVP80ES3 communication channel. Without message authentication codes or signatures, the device cannot distinguish authentic messages from tampered or injected ones.

Attack Vector

An attacker with network access to the DVP80ES3 sends manipulated protocol messages to the exposed communication interface. No credentials or user interaction are required. Delivery paths include direct network access, compromised engineering workstations, or lateral movement within the operational technology (OT) network segment.

Detailed protocol-level exploitation information is available in the Delta Security Advisory.

Detection Methods for CVE-2026-12576

Indicators of Compromise

  • Unexpected DVP80ES3 process halts, reboots, or communication timeouts on OT networks
  • Malformed or out-of-sequence PLC protocol frames observed in network captures
  • Connections to DVP80ES3 devices from hosts outside the engineering workstation allowlist

Detection Strategies

  • Deploy OT-aware intrusion detection to inspect Delta PLC protocol traffic for malformed messages
  • Baseline normal command sequences to the DVP80ES3 and alert on deviations
  • Correlate PLC availability events with adjacent network activity to identify triggering hosts

Monitoring Recommendations

  • Monitor DVP80ES3 device status, watchdog counters, and controller uptime
  • Log all network sessions to and from PLC IP addresses at network chokepoints
  • Alert when new source addresses initiate connections to the DVP80ES3 communication port

How to Mitigate CVE-2026-12576

Immediate Actions Required

  • Isolate DVP80ES3 devices on segmented OT networks with strict firewall rules
  • Restrict communication to the PLC to explicitly authorized engineering hosts
  • Review the Delta advisory and apply firmware updates when the vendor publishes them

Patch Information

Delta Electronics documents affected versions and remediation guidance in advisory Delta-PCSA-2026-00009. Consult the Delta Security Advisory for the vendor-supplied fix and installation instructions.

Workarounds

  • Place DVP80ES3 PLCs behind an industrial firewall that enforces deep packet inspection of Delta protocols
  • Disable remote access to the PLC communication channel from untrusted networks and the internet
  • Route management traffic through a jump host with multi-factor authentication and session logging
  • Implement network access control lists that permit only whitelisted engineering workstations to reach the device

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.