Description
Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-077/ |
|
History
Mon, 27 Jul 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise. | |
| Title | SSH Enablement Signature Verification Bypass | |
| First Time appeared |
Lenze
Lenze c4xx Firmware Lenze c5xx Firmware Lenze i950 Firmware |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:o:lenze:c4xx_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenze:c5xx_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Lenze
Lenze c4xx Firmware Lenze c5xx Firmware Lenze i950 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-07-27T07:03:27.889Z
Reserved: 2026-07-06T09:59:37.390Z
Link: CVE-2026-14837
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-347
Improper Verification of Cryptographic Signature