CVE 9.2 CRITICAL

Insecure generation of SAT access credentials in Ingecon EMS Board_CVE-2026-8072

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The vulnerability arose because the secret access credentials were not based on a secure cryptographic scheme, but rather on a weak hashing algorithm, which could allow an attacker to carry out a privilege escalation.

Basic Information

ID CVE-2026-8072
Source INCIBE
Published May 12, 2026 at 09:57

Affected Product

Vendor Ingeteam
Product Ingecon Sun EMS Board
Affected Versions Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0
Ingeteam Ingecon Sun EMS Board 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.