Danfoss AK-SM 800A
cpe:2.3:h:danfoss:ak-sm_800a:*:*:*:*:*:*:*, +1 more
- < 4.3.1
A command injection vulnerability has been identified in the Danfoss AK-SM800A Series, in versions prior to 4.3.1. This vulnerability arises from improper neutralization of alarm-to-mail configuration fields, which can be exploited to execute arbitrary commands on the system, potentially leading to post-authenticated remote code execution.
Exploitation of this vulnerability could allow for post-authenticated remote code execution on the affected system.
Users can upgrade to the latest AK-SM 800A software package version 4.3.1 to address this vulnerability. This version includes important cybersecurity enhancements. For systems already configured for HTTPS, the remote update will be straightforward. However, for those still using HTTP, an on-site update is recommended.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.