8.8
CVSSv3

CVE-2023-25556

Published: 18/04/2023 Updated: 28/04/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric merten_instabus_tastermodul_1fach_system_m_firmware 1.0

schneider-electric merten_instabus_tastermodul_2fach_system_m_firmware 1.0

schneider-electric merten_tasterschnittstelle_4fach_plus_firmware 1.0

schneider-electric merten_tasterschnittstelle_4fach_plus_firmware 1.2

schneider-electric merten_knx_argus_180\\/2\\,20m_up_system_firmware 1.0

schneider-electric merten_jalousie-\\/schaltaktor_reg-k\\/8x\\/16x\\/10_m._hb_firmware 1.0

schneider-electric merten_knx_uni-dimmaktor_ll_reg-k\\/2x230\\/300_w_firmware 1.0

schneider-electric merten_knx_uni-dimmaktor_ll_reg-k\\/2x230\\/300_w_firmware 1.1

schneider-electric merten_knx_schaltakt.2x6a_up_m.2_eing._firmware 0.1