The vendor explicitly identifies these products as affected by this CVE.
- SENTRON 7KT PAC1260 Data Manager
- Summary
- The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated attacker could be able to set the password to an attacker-controlled value.
- Remediation
- Do not access links from untrusted sources while logged in at affected devices
