Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions
Metrics
Affected Vendors & Products
References
History
Sun, 24 Aug 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Danfoss
Danfoss ak-sm8xxa Series |
|
| Vendors & Products |
Danfoss
Danfoss ak-sm8xxa Series |
Fri, 22 Aug 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 Aug 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions | |
| Title | Post auth nginx configuration injection in Danfoss AK-SM8xxA Series | |
| Weaknesses | CWE-15 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Danfoss
Published: 2025-08-22T02:40:53.563Z
Updated: 2025-08-22T10:52:36.122Z
Reserved: 2025-04-16T10:32:42.818Z
Link: CVE-2025-41452
Updated: 2025-08-22T10:52:29.432Z
Status : Awaiting Analysis
Published: 2025-08-22T03:15:30.207
Modified: 2025-08-22T18:08:51.663
Link: CVE-2025-41452
No data.
ReportizFlow