Impact
The vulnerability allows an attacker with limited remote privileges to change system configuration settings normally restricted to administrators, such as permission assignments. This results in a privilege escalation that compromises the integrity of device configuration and can enable further unauthorized actions. The weakness is an improper authorization flaw, identified as CWE‑863.
Affected Systems
Affected devices include the ads‑tec Industrial IT DVG series: DVG‑IRF1401, DVG‑IRF1421, DVG‑IRF3401, DVG‑IRF3421, DVG‑IRF3801, and DVG‑IRF3821. The firmware families IRF1000 and IRF3000 are mentioned as targets, but specific affected firmware versions are not listed in the advisory. Administrators should verify the model and firmware of their devices against the listed product identifiers.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, yet the EPSS score of less than 1% suggests that exploitation is currently rare. The advisory notes the flaw is exploitable by remote attackers with low privileges, thus likely via the configuration import interface. Because the issue is not listed in CISA KEV, there is no documented exploitation case, but the high impact makes timely remediation essential.
OpenCVE Enrichment