9.1
CVE-2025-41744
- EPSS 0.35%
- Veröffentlicht 02.12.2025 10:38:47
- Zuletzt bearbeitet 23.02.2026 17:15:02
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
Sprecher Automation: SPRECON-E series has static default key material for TLS connections
Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.27 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-1394 Use of Default Cryptographic Key
The product uses a default cryptographic key for potentially critical functionality.
https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/SPR-2511043_de.pdf