在 Danfoss iC7-Automation SP、iC7-Marine 和 iC7-Hybrid GR3 产品中,调试和工程接口的访问控制存在缺陷。攻击者可以利用暴露的服务接口和软件更新机制,读取和写入内部值,上传并执行未经签名的应用程序,以及上传未经签名的 EEPROM 数据和固件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Danfoss | iC7-Automation SP | ≤ 2025.3.3 |
affected |
| Danfoss | iC7-Hybrid | ≤ 2025.10.300845 |
affected |
| Danfoss | iC7-Marine | ≤ 2025.8.19 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Danfoss | iC7-Automation SP | 0 ~ 2025.3.3 | - |
|
| Danfoss | iC7-Marine | 0 ~ 2025.8.19 | - |
|
| Danfoss | iC7-Hybrid | 0 ~ 2025.10.300845 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet