CVE-2026-15203 PUBLISHED

Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software

Assigner: Danfoss
Reserved: 09.07.2026 Published: 26.08.2026 Updated: 26.08.2026

Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSS Score: 9.3

Product Status

Vendor Danfoss
Product iC7-Automation SP
Versions Default: unaffected
  • affected from 0 to 2025.3.3 (incl.)
Vendor Danfoss
Product iC7-Marine
Versions Default: unaffected
  • affected from 0 to 2025.8.19 (incl.)
Vendor Danfoss
Product iC7-Hybrid
Versions Default: unaffected
  • affected from 0 to 2025.10.300845 (incl.)

Solutions

  • iC7-Automation SP:  https://assets.danfoss.com/software/latest/572932/ID543724747716-0201.zip  (Release 2026.2.5-26A)
  • iC7-Marine:  https://assets.danfoss.com/software/latest/595833/ID506542766960-0501.zip  (Release 2026.6.30-GR4.4)
  • iC7-Hybrid:  https://assets.danfoss.com/software/latest/595835/ID506543688961-0601.zip  (Release 2026.7.2-GR4.5)

References

Problem Types

  • CWE-1191 On-Chip debug and test interface with improper access control CWE