Impact
The vulnerability, classified as CWE-347, is an improper signature verification in the SSH enablement mechanism. A local attacker who has low privilege can bypass the signature check, enable SSH, and gain administrative access, which can lead to full system compromise.
Affected Systems
Lenze devices c430, c520, c550, i950 GenA and i950 GenB are affected. The issue applies to all firmware releases of the c4xx, c5xx and i950 families.
Risk and Exploitability
The CVSS score is 8.5 and the EPSS score is < 1%, but the vulnerability is not listed in the CISA KEV catalog. The attack is likely carried out locally through privilege escalation; after enabling SSH, the attacker can remotely access the device and perform arbitrary actions.
OpenCVE Enrichment