Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Lenze c430
Lenze c550
Lenze i950 Gena
Lenze i950 Genb
Vendors & Products Lenze c430
Lenze c550
Lenze i950 Gena
Lenze i950 Genb

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
Title SSH Enablement Signature Verification Bypass
First Time appeared Lenze
Lenze c4xx Firmware
Lenze c5xx Firmware
Lenze i950 Firmware
Weaknesses CWE-347
CPEs cpe:2.3:o:lenze:c4xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:lenze:c5xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:*
Vendors & Products Lenze
Lenze c4xx Firmware
Lenze c5xx Firmware
Lenze i950 Firmware
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2026-07-27T07:03:27.889Z

Updated: 2026-07-27T14:01:50.573Z

Reserved: 2026-07-06T09:59:37.390Z

Link: CVE-2026-14837

cve-icon Vulnrichment

Updated: 2026-07-27T14:01:45.944Z

cve-icon NVD

No data.

cve-icon Redhat

No data.