CVE-2024-41794
CVSS 3.1 Score 10 of 10 (high)
Details
Summary
CVE-2024-41794 is a newly discovered vulnerability affecting all versions of SENTRON 7KT PAC1260 Data Manager. The issue involves hardcoded credentials granting unauthenticated remote access to the device operating system with root privileges. If the ssh service is enabled, an attacker with these credentials could gain full control over the device. This vulnerability poses a significant risk, as an attacker could exploit it to launch various malicious activities, potentially leading to data theft or system compromise. It is recommended that users of the affected device immediately disable the ssh service and apply the forthcoming patch to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.