CRITICAL🇵🇱 Wersja polska

CVE-2024-43698

CVSS 9.3v4.0pub. 2024-10-22upd. 2026-04-15

Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.

🤖 AI Analysis
How it works

The vulnerability results from the use of weak authentication mechanisms (CWE-1391 — use of weak credentials) that can be easily predicted or bypassed. A remote attacker with no privileges and without user interaction can exploit these weak credentials to obtain full administrative access to the device. Due to the network attack vector (AV:N) and lack of prerequisites (AC:L, PR:N, UI:N), the exploit is exceptionally easy to execute.

Impact

An attacker can obtain full administrator privileges on the device, allowing them to read, modify, or delete DDC4000 controller configuration and potentially disrupt the operation of building automation systems controlled by this device.

Mitigation & patch

Apply patches available from the manufacturer according to references (ICSA-24-291-05 available at https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-05). Additionally, it is recommended to immediately change default or weak credentials, isolate DDC4000 devices from the public network, and restrict access to management interfaces exclusively to authorized hosts (e.g., through firewall or network segmentation).

Who is affected

Kieback & Peter devices from the DDC4000 series — detailed information about hardware versions and firmware are indicated in the manufacturer references (ICS Advisory ICSA-24-291-05).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References