Skip to main content

External Control of System or Configuration Setting

CVE-2025-41452

Severity Medium
Score 6.8/10

Summary

Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions

  • HIGH
  • NETWORK
  • ACTIVE
  • HIGH

CWE-15 - External Control of System or Configuration Setting

One or more system settings or configuration elements can be externally controlled by a user.

References

Advisory Timeline

  • Published