SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15203

CRITICAL · CVSS 9.3 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Improper access control in Danfoss iC7-Automation, iC7-Marine, and iC7-Hybrid GR3 products allows attackers to exploit debug and engineering interfaces, potentially leading to unauthorized read/write access to internal values and the ability to upload and execute unsigned applications and firmware. This vulnerability poses a critical risk, as it can compromise system integrity and availability. Organizations using these products should prioritize immediate remediation to safeguard against potential exploitation.

CVE
CVE-2026-15203
Severity
CRITICAL
CVSS
9.3
EPSS
0.36%

Original NVD Description

Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms