Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 24 Aug 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Danfoss
Danfoss ak-sm8xxa Series
Vendors & Products Danfoss
Danfoss ak-sm8xxa Series

Fri, 22 Aug 2025 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 22 Aug 2025 03:00:00 +0000

Type Values Removed Values Added
Description Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions
Title Post auth nginx configuration injection in Danfoss AK-SM8xxA Series
Weaknesses CWE-15
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Danfoss

Published:

Updated: 2025-08-22T10:52:36.122Z

Reserved: 2025-04-16T10:32:42.818Z

Link: CVE-2025-41452

cve-icon Vulnrichment

Updated: 2025-08-22T10:52:29.432Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-22T03:15:30.207

Modified: 2025-08-22T18:08:51.663

Link: CVE-2025-41452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-23T17:27:27Z