Description
Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms
Published: 2026-08-26
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to read and modify internal configuration values, upload and run unsigned applications, and replace firmware and EEPROM data by exploiting exposed debug and engineering services. This improper access control can lead to full compromise of the affected device, granting the attacker control over the motor controller and any connected systems.

Affected Systems

Products affected are Danfoss iC7-Automation SP, iC7-Marine and iC7-Hybrid. The specific firmware revisions prior to the releases 2026.2.5-26A for iC7-Automation SP, 2026.6.30-GR4.4 for iC7-Marine and 2026.7.2-GR4.5 for iC7-Hybrid are vulnerable; exact earlier versions are not listed.

Risk and Exploitability

With a CVSS score of 9.3 the vulnerability is considered high severity. The EPSS score is not available, and there is no KEV listing, but the exposed service interfaces suggest a remote attack vector where an adversary can interact with the device over the network or via the update mechanism. If exploited, the attacker can upload and execute arbitrary code, effectively taking control of the device.

Generated by OpenCVE AI on August 26, 2026 at 06:20 UTC.

Remediation

Vendor Solution

* iC7-Automation SP:  https://assets.danfoss.com/software/latest/572932/ID543724747716-0201.zip  (Release 2026.2.5-26A) * iC7-Marine:  https://assets.danfoss.com/software/latest/595833/ID506542766960-0501.zip  (Release 2026.6.30-GR4.4) * iC7-Hybrid:  https://assets.danfoss.com/software/latest/595835/ID506543688961-0601.zip  (Release 2026.7.2-GR4.5)


OpenCVE Recommended Actions

  • Download and install the latest firmware updates from the links provided for the respective product
  • Reboot the device after applying the update to activate the changes
  • If the update cannot be applied immediately, block or disable the debug and engineering interfaces via the device configuration to prevent unauthenticated access until the patches are available

Generated by OpenCVE AI on August 26, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Description Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms
Title Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software
Weaknesses CWE-1191
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Danfoss

Published:

Updated: 2026-08-26T05:36:02.006Z

Reserved: 2026-07-09T06:41:49.174Z

Link: CVE-2026-15203

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T06:30:16Z

Weaknesses
  • CWE-1191

    On-Chip Debug and Test Interface With Improper Access Control