CVE-2026-15203CWE-1191

CVE-2026-15203

published August 26, 2026

CVSS
9.3
EPSS
0%
Percentile
29.1
In the wild
Unconfirmed
What it is

Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms

The record
Technical detail
CVSS
9.3 · NONE
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
EPSS
0.00361 · 29.1th percentile
Weakness
CWE-1191 · On-Chip Debug and Test Interface With Improper Access Control
Published
2026-08-26T10:16Z
References (3)
EPSS history
Timeline
  • 27 AUG 06:18Z
    EPSS moved — → 0%
    epss
  • 26 AUG 05:36Z
    Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software
    cvelistv5