Executive brief
VEGAPULS 6X is a radar sensor used for industrial level measurement in various manufacturing and processing environments. A security flaw in its configuration interface allows unauthorized individuals to access sensitive data, including login credentials and access codes. This could allow an attacker to take control of the device, potentially leading to unauthorized process changes or operational disruptions.
Technical details
A vulnerability exists in the configuration interface of VEGA VEGAPULS 6X radar sensors due to missing authentication for critical functions (CWE-306). Unauthenticated attackers can access the interface to retrieve sensitive information such as hashed credentials and access codes. While some advisory sources suggest an adjacent/Bluetooth vector, the primary NVD/CERT VDE entry indicates a network-based attack vector (AV:N). Successful exploitation allows an attacker to impersonate authorized users and potentially modify device configurations. Users are advised to update to fixed firmware versions and rotate all device credentials.
Affected products
- VEGA Grieshaber KG VEGAPULS 6X Firmware 1.0.0, 1.1.0
Timeline
- 2026-04-22: advisory: Initial advisory published by CERT VDE and VEGA
- 2026-04-28: disclosed: CVE-2026-3323 published