Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
* iC7-Automation SP: https://assets.danfoss.com/software/latest/572932/ID543724747716-0201.zip (Release 2026.2.5-26A) * iC7-Marine: https://assets.danfoss.com/software/latest/595833/ID506542766960-0501.zip (Release 2026.6.30-GR4.4) * iC7-Hybrid: https://assets.danfoss.com/software/latest/595835/ID506543688961-0601.zip (Release 2026.7.2-GR4.5)
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms | |
| Title | Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software | |
| Weaknesses | CWE-1191 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Danfoss
Published:
Updated: 2026-08-26T14:58:01.137Z
Reserved: 2026-07-09T06:41:49.174Z
Link: CVE-2026-15203
Updated: 2026-08-26T14:57:57.269Z
Status : Received
Published: 2026-08-26T06:16:25.130
Modified: 2026-08-26T15:16:43.550
Link: CVE-2026-15203
No data.
OpenCVE Enrichment
Updated: 2026-08-26T06:30:16Z
-
CWE-1191
On-Chip Debug and Test Interface With Improper Access Control