CVE-2025-41722
7.5Sauter · modulo 6 and EY-modulo 5 devices
The Sauter wsc server uses hard-coded certificates for SOAP message authentication, allowing unauthenticated remote attackers to extract private keys from the affected devices.
Executive summary
A critical vulnerability in Sauter modulo 6 and EY-modulo 5 devices allows unauthenticated remote attackers to extract private keys, compromising the authenticity of secure communications.
Vulnerability
The device utilizes a hard-coded certificate for SOAP message authentication (CWE-798). This flaw permits an unauthenticated remote attacker to retrieve sensitive private keys directly from the device software.
Business impact
The exploitation of this vulnerability results in the total loss of confidentiality regarding the cryptographic keys used for secure communication. With a CVSS score of 7.5, this high-severity flaw enables attackers to intercept or spoof SOAP messages, potentially allowing for unauthorized command injection or the disruption of industrial control processes. Such a compromise poses a significant risk to operational integrity and system security.
Remediation
Immediate Action: Update the affected Sauter devices to Firmware version v3.2.0 for modulo 6 units or version v6.0 for EY-modulo 5 units immediately upon availability from the vendor.
Proactive Monitoring: Review device access logs for unauthorized SOAP requests and monitor for anomalous traffic patterns directed at the wsc server interface.
Compensating Controls: Restrict network access to the wsc server interface using hardware firewalls or VLAN segmentation to ensure only authorized management segments can communicate with the devices.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high impact of private key exposure and the ease of exploitation over a network, this vulnerability requires urgent attention. Administrators should verify the current firmware version of all deployed Sauter units and prioritize the application of the vendor-supplied updates to eliminate the risk of unauthorized access and data interception.
Sources
Originally found and disclosed by Damian Pfammatter, Daniel Hulliger from Cyber-Defence Campus armasuisse S+T, per the CVE Program record.