Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Danfoss
Danfoss ic7-automation Sp Danfoss ic7-hybrid Danfoss ic7-marine |
|
| Vendors & Products |
Danfoss
Danfoss ic7-automation Sp Danfoss ic7-hybrid Danfoss ic7-marine |
Wed, 26 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms | |
| Title | Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software | |
| Weaknesses | CWE-1191 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Danfoss
Published: 2026-08-26T05:36:02.006Z
Updated: 2026-08-26T14:58:01.137Z
Reserved: 2026-07-09T06:41:49.174Z
Link: CVE-2026-15203
Updated: 2026-08-26T14:57:57.269Z
Status : Received
Published: 2026-08-26T06:16:25.130
Modified: 2026-08-26T15:16:43.550
Link: CVE-2026-15203
No data.