Description
Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms
Published: 2026-08-26
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to read and modify internal configuration values, upload and run unsigned applications, and replace firmware and EEPROM data by exploiting exposed debug and engineering services. This improper access control can lead to full compromise of the affected device, granting the attacker control over the motor controller and any connected systems.

Affected Systems

Products affected are Danfoss iC7-Automation SP, iC7-Marine and iC7-Hybrid. The specific firmware revisions prior to the releases 2026.2.5-26A for iC7-Automation SP, 2026.6.30-GR4.4 for iC7-Marine and 2026.7.2-GR4.5 for iC7-Hybrid are vulnerable; exact earlier versions are not listed.

Risk and Exploitability

With a CVSS score of 9.3 the vulnerability is considered high severity. The EPSS score is not available, and there is no KEV listing, but the exposed service interfaces suggest a remote attack vector where an adversary can interact with the device over the network or via the update mechanism. If exploited, the attacker can upload and execute arbitrary code, effectively taking control of the device.

Generated by OpenCVE AI on August 26, 2026 at 06:20 UTC.

Remediation

Vendor Solution

* iC7-Automation SP:  https://assets.danfoss.com/software/latest/572932/ID543724747716-0201.zip  (Release 2026.2.5-26A) * iC7-Marine:  https://assets.danfoss.com/software/latest/595833/ID506542766960-0501.zip  (Release 2026.6.30-GR4.4) * iC7-Hybrid:  https://assets.danfoss.com/software/latest/595835/ID506543688961-0601.zip  (Release 2026.7.2-GR4.5)


OpenCVE Recommended Actions

  • Download and install the latest firmware updates from the links provided for the respective product
  • Reboot the device after applying the update to activate the changes
  • If the update cannot be applied immediately, block or disable the debug and engineering interfaces via the device configuration to prevent unauthenticated access until the patches are available

Generated by OpenCVE AI on August 26, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Danfoss
Danfoss ic7-automation Sp
Danfoss ic7-hybrid
Danfoss ic7-marine
Vendors & Products Danfoss
Danfoss ic7-automation Sp
Danfoss ic7-hybrid
Danfoss ic7-marine

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Description Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms
Title Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software
Weaknesses CWE-1191
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

Danfoss Ic7-automation Sp Ic7-hybrid Ic7-marine
cve-icon MITRE

Status: PUBLISHED

Assigner: Danfoss

Published:

Updated: 2026-08-26T14:58:01.137Z

Reserved: 2026-07-09T06:41:49.174Z

Link: CVE-2026-15203

cve-icon Vulnrichment

Updated: 2026-08-26T14:57:57.269Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T06:16:25.130

Modified: 2026-09-03T16:41:09.297

Link: CVE-2026-15203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:33:50Z

Weaknesses
  • CWE-1191

    On-Chip Debug and Test Interface With Improper Access Control