CVE-2026-3323

HIGH

VEGA: Privilege escalation through unsecured configuration interface in VEGAPULS devices

Title source: cna
STIX 2.1

Description

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
VEGA Grieshaber/VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL) 1.0.0
VEGA Grieshaber/VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL) 1.1.0
Published Apr 28, 2026
Tracked Since Apr 28, 2026