External Control of System or Configuration Setting
CVE-2025-41452
Summary
Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions
- HIGH
- NETWORK
- ACTIVE
- HIGH
CWE-15 - External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
References
Advisory Timeline
- Published