Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited information about the architecture and internal processes.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSprecher Automation Sprecon E C
HWSprecher-Automationall versionsSprecher Automation Sprecon E C Firmware
OSSprecher-Automation< 9.0Sprecher Automation Sprecon E P
HWSprecher-Automationall versionsSprecher Automation Sprecon E P Firmware
OSSprecher-Automation< 9.0Sprecher Automation Sprecon E T3
HWSprecher-Automationall versionsSprecher Automation Sprecon E T3 Firmware
OSSprecher-Automation< 9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-41742CRITICAL9.8PL ✓same product
Sprecher-Automation Sprecon-E: domyślne klucze kryptograficzne umożliwiają pełny dostęp zdalny
CVE-2025-41744CRITICAL9.1PL ✓same product
Domyślne klucze kryptograficzne w urządzeniach Sprecher Automation SPRECON-E
CVE-2022-4333CRITICAL9.8PL ✓same product
Hardcoded Credentials w urządzeniach SPRECON-E CPU firmy Sprecher Automation
CVE-2024-6758MEDIUM6.5same product
Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker wi...
CVE-2022-4332MEDIUM6.8same product
In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been iden...