Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-044/ |
|
History
Tue, 27 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 May 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise. | |
| Title | Weidmueller: Missing Authentication Vulnerability in Industrial Ethernet Switches | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-05-27T08:38:03.213Z
Updated: 2025-05-27T13:26:59.857Z
Reserved: 2025-04-16T11:17:48.305Z
Link: CVE-2025-41651
Updated: 2025-05-27T13:25:47.296Z
Status : Awaiting Analysis
Published: 2025-05-27T09:15:21.380
Modified: 2025-05-28T15:01:30.720
Link: CVE-2025-41651
No data.