Improper Authentication vulnerability in Danfoss AK-SM8xxA Series, resulting in an authentication bypass
Advisory Information
Advisory ID: DSA-2025-03-01
- CVE numbers and CVSS scores
- CVE-2025-41450
Base Score: 8.2 (HIGH)
- CVE-2025-41450
Summary
Improper Authentication vulnerability in Danfoss AK-SM8xxA Series, resulting in an authentication bypass. Install the latest patch with number 4.2 to remediate this vulnerability.
Affected products and services
- Danfoss AK-SM 8xxA Series prior to version 4.2
Vulnerability description
CVE-2025-41450 - Improper Authentication vulnerability in Danfoss AK-SM8xxA Series.
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.
Problem Type: CWE-287: Improper Authentication
Remediations
- Install the latest software version through AK-SM 800A Series | Danfoss.
Mitigations
- N/A
Credits (if opted in)
- Tomer Goldschmidt (Claroty Team82)
Update log
- 24 March, 2025: Publication