CVE-2025-41722

7.5

Sauter · modulo 6 and EY-modulo 5 devices

The Sauter wsc server uses hard-coded certificates for SOAP message authentication, allowing unauthenticated remote attackers to extract private keys from the affected devices.

Executive summary

A critical vulnerability in Sauter modulo 6 and EY-modulo 5 devices allows unauthenticated remote attackers to extract private keys, compromising the authenticity of secure communications.

Vulnerability

The device utilizes a hard-coded certificate for SOAP message authentication (CWE-798). This flaw permits an unauthenticated remote attacker to retrieve sensitive private keys directly from the device software.

Business impact

The exploitation of this vulnerability results in the total loss of confidentiality regarding the cryptographic keys used for secure communication. With a CVSS score of 7.5, this high-severity flaw enables attackers to intercept or spoof SOAP messages, potentially allowing for unauthorized command injection or the disruption of industrial control processes. Such a compromise poses a significant risk to operational integrity and system security.

Remediation

Immediate Action: Update the affected Sauter devices to Firmware version v3.2.0 for modulo 6 units or version v6.0 for EY-modulo 5 units immediately upon availability from the vendor.

Proactive Monitoring: Review device access logs for unauthorized SOAP requests and monitor for anomalous traffic patterns directed at the wsc server interface.

Compensating Controls: Restrict network access to the wsc server interface using hardware firewalls or VLAN segmentation to ensure only authorized management segments can communicate with the devices.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high impact of private key exposure and the ease of exploitation over a network, this vulnerability requires urgent attention. Administrators should verify the current firmware version of all deployed Sauter units and prioritize the application of the vendor-supplied updates to eliminate the risk of unauthorized access and data interception.

Sources

Originally found and disclosed by Damian Pfammatter, Daniel Hulliger from Cyber-Defence Campus armasuisse S+T, per the CVE Program record.