← Back to browse · API

CVE-2024-41794

Severity
CRITICAL
CVSS
10.0
EPSS
0.00614
Risk score
40.21
CISA KEV
No
PoC
No
Published
2025-04-08
Modified
2025-04-08
First seen
2026-08-07
Aliases
EUVD-2025-10329, GHSA-W4WQ-MMWQ-2C74
Products
Siemens:SENTRON 7KT PAC1260 Data Manager 0 <*
Sources
euvd EUVD-2025-10329

Description

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for remote access to the device operating system with root privileges. This could allow unauthenticated remote attackers to gain full access to a device, if they are in possession of these credentials and if the ssh service is enabled (e.g., by exploitation of CVE-2024-41793).

References