Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptographic keys in system components
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
In short
Sprecher Automation SPRECON-E devices use fixed, unchangeable encryption keys that attackers can exploit remotely. This allows unauthorized access to read, modify system projects, steal data, and take control of devices without needing a password.
Technical detail
SPRECON-E series controllers are vulnerable to remote cryptographic key exploitation due to static, hardcoded keys in firmware. An unauthenticated remote attacker can leverage these keys to intercept and modify project configurations, exfiltrate sensitive data, or establish unauthorized remote maintenance sessions, resulting in complete system compromise.
Summary generated and translated by AI from the official description.
Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H