PT-2024-7912 · Sprecher Automation · Sprecon-E

Sprecher Automation

·

Published

2024-07-17

·

Updated

2025-08-22

·

CVE-2024-6758

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Sprecher Automation SPRECON-E versions prior to 8.71j
Description The issue is related to improper privilege management, allowing a remote attacker with low privileges to save unauthorized protection assignments. This can be achieved through specially crafted HTTP(S) requests, potentially enabling the attacker to modify the device's configuration.
Recommendations For versions prior to 8.71j, upgrade to version 8.71j or later to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the device to minimize the risk of unauthorized configuration changes.

Fix

Improper Privilege Management

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2024-09416
CVE-2024-6758

Affected Products

Sprecon-E