Description
The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys from the Software of the affected devices.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
0.0.0 (semver) before Firmware v3.2.0
0.0.0 (semver) before Firmware v3.2.0
0.0.0 (semver) before Firmware v3.2.0
0.0 (semver) before Firmware v6.0
0.0 (semver) before Firmware v6.0
0.0 (semver) before Firmware v6.0
Credits
Damian Pfammatter, Daniel Hulliger from Cyber-Defence Campus armasuisse S+T
References
sauter.csaf-tp.certvde.com/...f/white/2025/vde-2025-060.json