PT-2023-1974 · Merten · Merten Knx

Published

2023-02-14

·

Updated

2023-04-28

·

CVE-2023-25556

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Merten KNX (affected versions not specified)
Description A vulnerability exists due to improper authentication, which could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation. This issue is related to weaknesses in the authentication procedure. An attacker, acting remotely, could exploit this vulnerability to gain access to the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-01595
CVE-2023-25556

Affected Products

Merten Knx