2026-04-28 10:24CVE-2026-3323CERTVDE
PUBLISHED5.2CWE-306

VEGA: Privilege escalation through unsecured configuration interface in VEGAPULS devices

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

Problem type

Affected products

VEGA Grieshaber

VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL)

1.0.0 - AFFECTED

VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL)

1.1.0 - AFFECTED

References

GitHub Security Advisories

GHSA-rjqm-m642-mm46

An unsecured configuration interface on affected devices allows unauthenticated remote attackers...

https://github.com/advisories/GHSA-rjqm-m642-mm46

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-3323
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-3323",
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "dateUpdated": "2026-04-28T10:24:19.411Z",
    "dateReserved": "2026-02-27T11:10:05.931Z",
    "datePublished": "2026-04-28T10:24:19.411Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE",
        "dateUpdated": "2026-04-28T10:24:19.411Z"
      },
      "datePublic": "2026-04-22T10:00:00.000Z",
      "title": "VEGA: Privilege escalation through unsecured configuration interface in VEGAPULS devices",
      "descriptions": [
        {
          "lang": "en",
          "value": "An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.<br>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "VEGA Grieshaber",
          "product": "VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL)",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0.0",
              "status": "affected"
            }
          ]
        },
        {
          "vendor": "VEGA Grieshaber",
          "product": "VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL)",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.1.0",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-306 Missing Authentication for Critical Function",
              "cweId": "CWE-306",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://certvde.com/en/advisories/VDE-2026-016",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://vega.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-016.json",
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Product Security Unit at VEGA Grieshaber KG",
          "user": "00000000-0000-4000-9000-000000000000",
          "type": "finder"
        }
      ]
    }
  }
}