← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE EPSS 0.00

VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

[VDE-2026-046] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.

Číst originál na CERT@VDE →

4 zprávy z 1 zdroje · první 22. 6. 12:00 · poslední 24. 6. 12:00 CZ · EN/orig

VEGA DE

tg: zranitelnost tp: identita tp: průmyslové systémy

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-3323 7.5 3.1 · CERTVDE 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Jak se o tom psalo 4

  1. · CERT@VDE DE nadpis události

    VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

    [VDE-2026-046] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.

  2. · CERT@VDE DE

    VEGA: Unsecured Configuration Interface Allows Unauthorized Access Leading to Privilege Escalation

    [VDE-2026-016] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.

  3. · CERT@VDE DE

    VEGA: Missing Authentication for critical function in VEGAPULS Bluetooth products

    [VDE-2026-048] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.

  4. · CERT@VDE DE

    VEGA: Missing Authentication for critical function in VEGAPULS Air products

    [VDE-2026-047] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.