Executive brief
Danfoss iC7 industrial automation controllers contain inadequate access controls on debug and engineering interfaces, allowing unauthenticated attackers to modify system settings, execute arbitrary code, and modify firmware. This could enable unauthorized changes to critical industrial operations, system compromise, or service disruption in manufacturing and marine environments.
Technical details
The vulnerability stems from improper access control in debug and engineering service interfaces exposed in Danfoss iC7 controllers (Automation SP, Marine, and Hybrid GR3 models). The exposed interfaces allow attackers to read and write internal values without proper authentication, upload and execute unsigned applications, and modify EEPROM data and firmware via unprotected software update mechanisms. No authentication appears to be enforced on these interfaces, and the attack vector is network-accessible. An attacker can achieve arbitrary code execution and full system compromise. Patches are available from Danfoss via the referenced software updates.
Affected products
- Danfoss iC7-Automation SP <UNKNOWN>
- Danfoss iC7-Marine <UNKNOWN>
- Danfoss iC7-Hybrid GR3 <UNKNOWN>
Timeline
- 2026-08-26: disclosed