CVE-2026-3323
7.5VEGA Grieshaber · VEGAPULS 6X
The VEGAPULS 6X sensor features an unsecured configuration interface that allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.
Executive summary
A high-severity authentication flaw in VEGA Grieshaber VEGAPULS 6X sensors enables unauthenticated remote attackers to exfiltrate sensitive configuration data and credentials.
Vulnerability
This vulnerability involves a missing authentication check for a critical configuration interface (CWE-306). It allows any unauthenticated remote attacker to gain unauthorized access to sensitive system information.
Business impact
Successful exploitation of this vulnerability poses a severe risk to operational security, as it grants attackers access to hashed credentials and access codes. Given the CVSS score of 7.5, this high-severity flaw could lead to full device compromise or lateral movement within industrial control networks. Such unauthorized access may result in significant operational disruption, data theft, and loss of integrity for critical sensor configurations.
Remediation
Immediate Action: Restrict network access to the affected devices immediately by placing them behind a secure gateway or firewall, as an official patch status remains unknown.
Proactive Monitoring: Monitor network traffic for unauthorized connection attempts to the device configuration ports and review all access logs for suspicious activity.
Compensating Controls: Implement strict network segmentation to ensure the affected devices are not exposed to the public internet or untrusted network segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The exposure of hashed credentials and access codes on industrial sensors constitutes a significant security risk that must be addressed immediately. Organizations should prioritize isolating these devices from external networks and coordinating with the vendor to obtain firmware updates as soon as they become available.
More VEGA Grieshaber CVEs
Sources
Originally found and disclosed by Product Security Unit at VEGA Grieshaber KG, per the CVE Program record.