Status: UPDATED
| Advisory ID: CVE-2026-3323
Key Details
| CVE | CVE-2026-3323 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | Vega vegapuls_6x_firmware and VEGA Grieshaber VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL) |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.
What to Do
Monitor Vega's and VEGA Grieshaber's web pages for any future patch releases.
References