CVE 9.1 CRITICAL

Sprecher Automation: SPRECON-E series has static default key material for TLS connections_CVE-2025-41744

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.

AI Analysis

Default cryptographic keys allow unprivileged remote access to encrypted communications, compromising confidentiality and integrity.

Basic Information

ID CVE-2025-41744
Source CERTVDE
Published Dec 2, 2025 at 10:38

Affected Product

Vendor Sprecher Automation
Product SPRECON-E-C
Version *
Affected Versions Sprecher Automation SPRECON-E-C *
Sprecher Automation SPRECON-E-P *
Sprecher Automation SPRECON-E-T3 *

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor Sprecher Automation
Product SPRECON-E series
Version *

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.