Project Subscriptions
No data.
No advisories yet.
Solution
* iC7-Automation SP: https://assets.danfoss.com/software/latest/572932/ID543724747716-0201.zip (Release 2026.2.5-26A) * iC7-Marine: https://assets.danfoss.com/software/latest/595833/ID506542766960-0501.zip (Release 2026.6.30-GR4.4) * iC7-Hybrid: https://assets.danfoss.com/software/latest/595835/ID506543688961-0601.zip (Release 2026.7.2-GR4.5)
Workaround
No workaround given by the vendor.
Wed, 26 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms | |
| Title | Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software | |
| Weaknesses | CWE-1191 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Danfoss
Published:
Updated: 2026-08-26T05:36:02.006Z
Reserved: 2026-07-09T06:41:49.174Z
Link: CVE-2026-15203
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T06:30:16Z