This security advisory addresses one vulnerability identified in Serial Device Servers.
CVE-2026-10831
Improper Authorization of Break Signal Commands in Devices
A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not properly validate whether a sender is associated with a valid data port session before accepting break signal commands. A remote attacker with network access can send crafted requests to disrupt serial communication for an active user session.
Because the issue is assessed as medium severity, users can evaluate their environment and schedule the update in the next maintenance or update cycle.
The Identified Vulnerability Type and Potential Impact
| CVE ID |
Vulnerability Type |
Impact |
| CVE-2026-10831 |
CWE-862: Missing Authorization
|
CAPEC-212: Functionality Misuse |
Vulnerability Scoring Details
|
CVE ID
|
Base Score
|
Vector
|
Severity |
Unauthenticated
Remote Exploits
|
| CVE-2026-10831 |
CVSS 4.0: 6.9 |
AV:N/AC:L/AT:N/PR:N/UI:N/
VC:N/VI:L/VA:L/SC:N/SI:N/SA:L
|
Medium |
Yes |