Summary
The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.
Impact
This vulnerability could compromise the confidentiality, integrity, and availability of the product.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| c430 | Firmware c4x0 <1.15.2 | |
| c520 | Firmware c5x0 <1.15.2 | |
| c550 | Firmware c5x0 <1.15.2 | |
| i950 GenA | Firmware i950 <1.14.2 | |
| i950 GenB | Firmware i950 <2.0.2 |
Vulnerabilities
Expand / Collapse allMultiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
Mitigation
Check to see if there is an activation file on the SD Card, and delete it. In addition, it is recommended that you protect each access path with appropriate measures, such as physically securing access to the SD Card, authorizing file transfers via PLC Designer (if supported by the respective product), authorizing file transfers via OPC UA (if supported by the respective product), and customizing the key for SFTP access.
Remediation
To resolve this security vulnerability, we recommend installing a firmware update.
| Product | Firmware | Fixed Version |
|---|---|---|
| Controller c430 | c4xx | 1.15.2 |
| c520 | c5xx | 1.15.2 |
| c550 | c5xx | 1.15.2 |
| i950 GenA | i950 | 1.15.0 |
| i950 GenB | i950 | 2.0.3 |
Acknowledgments
Lenze SE thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 07/27/2026 12:00 | Initial release. |