A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated attacker could be able to set the password to an attacker-controlled value.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens 7kt Pac1260 Data Manager Siemens 7kt Pac1260 Data Manager Firmware |
|
CPEs | cpe:2.3:h:siemens:7kt_pac1260_data_manager:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:7kt_pac1260_data_manager_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Siemens
Siemens 7kt Pac1260 Data Manager Siemens 7kt Pac1260 Data Manager Firmware |
Tue, 08 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Apr 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated attacker could be able to set the password to an attacker-controlled value. | |
Weaknesses | CWE-620 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published: 2025-04-08T08:22:14.357Z
Updated: 2025-04-08T13:31:32.350Z
Reserved: 2024-07-22T13:19:53.377Z
Link: CVE-2024-41796

Updated: 2025-04-08T13:31:26.321Z

Status : Analyzed
Published: 2025-04-08T09:15:20.813
Modified: 2025-09-23T16:02:23.133
Link: CVE-2024-41796

No data.