CVE-2026-3323
HIGHVEGA: Privilege escalation through unsecured configuration interface in VEGAPULS devices
Title source: cnaDescription
An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.
Scores
CVSS v3
7.5
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (2)
VEGA Grieshaber/VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL)
1.0.0
VEGA Grieshaber/VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL)
1.1.0
Published
Apr 28, 2026
Tracked Since
Apr 28, 2026