CVE-2026-3323

1 karet z 4 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2026-3323

EPSS 0.00 EPSS k 18. 9. 2026

Hodnocení závažnosti

7.5 CVSS 3.1 CERTVDE

útok odkudkoli z internetu bez přípravy bez přihlášení bez zásahu uživatele
dopad plný únik dat beze změny dat bez výpadku
přesah dopad jen na zranitelnou součást

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

1

SPOJENO PŘES CVE VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

[VDE-2026-046] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.

EPSS 0.00 CVE-2026-3323 VEGA DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products