PT-2025-23783 · Unknown · Eibport V3 Knx+1
Published
2025-06-04
·
Updated
2025-10-08
·
CVE-2024-13967
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EIBPORT V3 KNX versions 3.9.8 and earlier
EIBPORT V3 KNX GSM versions 3.9.8 and earlier
Description
This issue allows a successful attacker to gain unauthorized access to a configuration web page delivered by the integrated web server of EIBPORT.
Recommendations
For EIBPORT V3 KNX versions 3.9.8 and earlier, update to a version later than 3.9.8 to resolve the issue.
For EIBPORT V3 KNX GSM versions 3.9.8 and earlier, update to a version later than 3.9.8 to resolve the issue.
As a temporary workaround, consider restricting access to the integrated web server until a patch is available.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eibport V3 Knx
Eibport V3 Knx Gsm