CVE-2024-6758
MEDIUMSprecher Automation SPRECON-E <8.71j - Privilege Escalation
Title source: llmDescription
Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low privileges to save unauthorized protection assignments.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/SPR-2407171_de.pdf
Scores
CVSS v3
6.5
EPSS
0.0044
EPSS Percentile
35.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-266
Status
published
Products (12)
sprecher-automation/sprecon-e-c_firmware
< 8.71j
sprecher-automation/sprecon-e-p_dd6-2_firmware
< 8.71j
sprecher-automation/sprecon-e-p_dl6-1_firmware
< 8.71j
sprecher-automation/sprecon-e-p_dq6-1_firmware
< 8.71j
sprecher-automation/sprecon-e-p_ds6-0_firmware
< 8.71j
sprecher-automation/sprecon-e-t3_ax-3110_firmware
< 8.71j
sprecher-automation/sprecon-e-t3_firmware
< 8.71j
sprecher-automation/sprecon-e_ap-2200_firmware
< 8.71j
sprecher-automation/sprecon-e_cp-2131_firmware
< 8.71j
sprecher-automation/sprecon-e_cp-2330_firmware
< 8.71j
... and 2 more
Published
Aug 12, 2024
Tracked Since
Feb 18, 2026