A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 to April 2025). The maintenance connection of affected devices fails to protect access to the device's control unit configuration. This could allow an attacker with physical access to the maintenance connection's door port to perform arbitrary configuration changes.
History

Thu, 12 Jun 2025 05:30:00 +0000

Type Values Removed Values Added
References

Wed, 11 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Jun 2025 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 to April 2025). The maintenance connection of affected devices fails to protect access to the device's control unit configuration. This could allow an attacker with physical access to the maintenance connection's door port to perform arbitrary configuration changes.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2025-06-11T06:55:31.200Z

Updated: 2025-06-12T05:13:25.889Z

Reserved: 2024-05-15T15:36:13.543Z

Link: CVE-2024-35295

cve-icon Vulnrichment

Updated: 2025-06-11T13:21:33.969Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-11T07:15:24.273

Modified: 2025-06-12T16:06:20.180

Link: CVE-2024-35295

cve-icon Redhat

No data.