Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.
The vulnerability results from the use of weak authentication mechanisms (CWE-1391 — use of weak credentials) that can be easily predicted or bypassed. A remote attacker with no privileges and without user interaction can exploit these weak credentials to obtain full administrative access to the device. Due to the network attack vector (AV:N) and lack of prerequisites (AC:L, PR:N, UI:N), the exploit is exceptionally easy to execute.
An attacker can obtain full administrator privileges on the device, allowing them to read, modify, or delete DDC4000 controller configuration and potentially disrupt the operation of building automation systems controlled by this device.
Apply patches available from the manufacturer according to references (ICSA-24-291-05 available at https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-05). Additionally, it is recommended to immediately change default or weak credentials, isolate DDC4000 devices from the public network, and restrict access to management interfaces exclusively to authorized hosts (e.g., through firewall or network segmentation).
Kieback & Peter devices from the DDC4000 series — detailed information about hardware versions and firmware are indicated in the manufacturer references (ICS Advisory ICSA-24-291-05).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X