CVE-2026-3323 Details
Description
An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.
A vulnerability exists in the VEGA Grieshaber VEGAPULS 6X model, specifically in the two-wire PROFINET, Modbus TCP, and OPC UA (Ethernet-APL) versions 1.0.0 and 1.1.0. The issue arises from an unsecured configuration interface that permits unauthenticated remote access to sensitive information, such as hashed credentials and access codes. This vulnerability could lead to unauthorized users impersonating authorized ones and potentially modifying device settings.
Users are advised to update to the fixed firmware version 1.1.1. After the update, any credentials used on affected devices should be rotated, as they may have been compromised. If emergency code rotation is necessary, VEGA Support can be contacted.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/en/advisories/VDE-2026-016 | [email protected] | Third Party Advisory |
| https://vega.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-016.json | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vega vegapuls 6x firmware | 1.0.0 1.1.0 |
CPE
Remediation
| |
| vega vegapuls 6x | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | Initial Analysis | [email protected] |
| Apr 28, 2026 | New CVE Received | [email protected] |