• My Apps
    My Apps You will have the option to use My apps once you login.

DSA-2025-03-01

Improper Authentication vulnerability in Danfoss AK-SM8xxA Series, resulting in an authentication bypass

Advisory Information

Advisory ID: DSA-2025-03-01

Summary

Improper Authentication vulnerability in Danfoss AK-SM8xxA Series, resulting in an authentication bypass. Install the latest patch with number 4.2 to remediate this vulnerability.

Affected products and services

  • Danfoss AK-SM 8xxA Series prior to version 4.2

Vulnerability description

CVE-2025-41450 - Improper Authentication vulnerability in Danfoss AK-SM8xxA Series.
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.
Problem Type: CWE-287: Improper Authentication 

Remediations

Mitigations

  • N/A

Credits (if opted in)

  1. Tomer Goldschmidt (Claroty Team82)

Other reference

Update log

  • 24 March, 2025: Publication