CVE Vulnerabilities

CVE-2024-41796

Unverified Password Change

Published: Apr 08, 2025 | Modified: Sep 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated attacker could be able to set the password to an attacker-controlled value.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

Name Vendor Start Version End Version
7kt_pac1260_data_manager_firmware Siemens * *

Potential Mitigations

References