Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
VC:00 (semver)
affected
Default status
unaffected
VC:00 (semver)
affected
Default status
unaffected
VC:00 (semver)
affected
Default status
unaffected
VC:00 (semver)
affected
Description
An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
VC:00 (semver)
VC:00 (semver)
VC:00 (semver)
VC:00 (semver)
Credits
D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube Security Research
References
seclists.org/fulldisclosure/2025/Oct/12
certvde.com/de/advisories/VDE-2025-072