Home

Description

Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The vulnerability arose because the secret access credentials were not based on a secure cryptographic scheme, but rather on a weak hashing algorithm, which could allow an attacker to carry out a privilege escalation.

PUBLISHED Reserved 2026-05-07 | Published 2026-05-12 | Updated 2026-05-12 | Assigner INCIBE




CRITICAL: 9.2CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-327: Use of a Broken or Risky Cryptographic Algorithm

Product status

Default status
unaffected

Any version
affected

Any version
affected

Any version
affected

Any version
affected

Any version
affected

Any version
affected

Any version
affected

Any version
affected

Any version
affected

Any version
affected

AAX1055CU
unaffected

ABU1001_Q
unaffected

ACL1201_C
unaffected

ACL1200AM
unaffected

ABH1027_L
unaffected

ABH1007AA
unaffected

ABS1009_P
unaffected

ABS1005_U
unaffected

ACB1005_C
unaffected

AAX1031CO
unaffected

Credits

Rubén Santamarta finder

References

www.incibe.es/...on-sat-access-credentials-ingecon-ems-board patch

www.reversemode.com/...tical-analysis-of-cyber-physical.html

cve.org (CVE-2026-8072)

nvd.nist.gov (CVE-2026-8072)

Download JSON