CVE-2024-41794

CVSS 3.1 Score 10 of 10 (high)

Details

Published Apr 8, 2025
CWE ID 798

Summary

CVE-2024-41794 is a newly discovered vulnerability affecting all versions of SENTRON 7KT PAC1260 Data Manager. The issue involves hardcoded credentials granting unauthenticated remote access to the device operating system with root privileges. If the ssh service is enabled, an attacker with these credentials could gain full control over the device. This vulnerability poses a significant risk, as an attacker could exploit it to launch various malicious activities, potentially leading to data theft or system compromise. It is recommended that users of the affected device immediately disable the ssh service and apply the forthcoming patch to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share