No advisories yet.
Solution
The risk has been mitigated with the release of a patch applicable to all versions, developed in December 2025. It is recommended that users update to the newer versions.
Workaround
No workaround given by the vendor.
Tue, 12 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The vulnerability arose because the secret access credentials were not based on a secure cryptographic scheme, but rather on a weak hashing algorithm, which could allow an attacker to carry out a privilege escalation. | |
| Title | Insecure generation of SAT access credentials in Ingecon EMS Board | |
| First Time appeared |
Ingeteam
Ingeteam ingecon Sun Ems Board |
|
| Weaknesses | CWE-327 | |
| CPEs | cpe:2.3:a:ingeteam:ingecon_sun_ems_board:*:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:aax1031co:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:aax1055cu:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:abh1007aa:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:abh1027_l:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:abs1005_u:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:abs1009_p:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:abu1001_q:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:acb1005_c:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:acl1200am:*:*:*:*:*:*:* cpe:2.3:a:ingeteam:ingecon_sun_ems_board:acl1201_c:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ingeteam
Ingeteam ingecon Sun Ems Board |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-05-12T12:19:29.775Z
Reserved: 2026-05-07T09:46:15.152Z
Link: CVE-2026-8072
Updated: 2026-05-12T12:19:15.314Z
Status : Received
Published: 2026-05-12T10:16:48.670
Modified: 2026-05-12T10:16:48.670
Link: CVE-2026-8072
No data.
OpenCVE Enrichment
Updated: 2026-05-12T11:30:14Z