A CWE-287: Improper Authentication vulnerability exists that could allow a device to be
compromised when a key of less than seven digits is entered and the attacker has access to the
KNX installation.

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
Merten Instabus Tastermodul 1fach System M Subscribe
Merten Instabus Tastermodul 1fach System M Firmware Subscribe
Merten Instabus Tastermodul 2fach System M Subscribe
Merten Instabus Tastermodul 2fach System M Firmware Subscribe
Merten Jalousie-\/schaltaktor Reg-k\/8x\/16x\/10 M. Hb Subscribe
Merten Jalousie-\/schaltaktor Reg-k\/8x\/16x\/10 M. Hb Firmware Subscribe
Merten Knx Argus 180\/2\,20m Up System Subscribe
Merten Knx Argus 180\/2\,20m Up System Firmware Subscribe
Merten Knx Schaltakt.2x6a Up M.2 Eing. Subscribe
Merten Knx Schaltakt.2x6a Up M.2 Eing. Firmware Subscribe
Merten Knx Uni-dimmaktor Ll Reg-k\/2x230\/300 W Subscribe
Merten Knx Uni-dimmaktor Ll Reg-k\/2x230\/300 W Firmware Subscribe
Merten Tasterschnittstelle 4fach Plus Subscribe
Merten Tasterschnittstelle 4fach Plus Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-29508 A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2025-02-05T21:15:50.417Z

Reserved: 2023-02-07T17:00:03.780Z

Link: CVE-2023-25556

cve-icon Vulnrichment

Updated: 2024-08-02T11:25:19.293Z

cve-icon NVD

Status : Modified

Published: 2023-04-18T18:15:07.357

Modified: 2024-11-21T07:49:43.417

Link: CVE-2023-25556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses