Web Interface Vulnerability in SENTRON Data Manager by Siemens
CVE-2024-41796
6.9MEDIUM
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 8 April 2025
What is CVE-2024-41796?
A vulnerability exists in the web interface of the SENTRON 7KT PAC1260 Data Manager, allowing changes to login passwords without requiring the current password. This vulnerability can be exploited in conjunction with a crafted CSRF attack, enabling an unauthenticated attacker to set the password to a value of their choosing, posing a significant risk to device security.
Affected Version(s)
SENTRON 7KT PAC1260 Data Manager 0