TRUMPF TruTops default user accounts vulnerability
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
TRUMPF Werkzeugmaschinen SE + Co. KG · Job Order InterfaceTRUMPF Werkzeugmaschinen SE + Co. KG · OseonTRUMPF Werkzeugmaschinen SE + Co. KG · TruTops Boost with option Graphic separation of cut partsTRUMPF Werkzeugmaschinen SE + Co. KG · TruTops Boost with option Inventory of sheets and remainder sheetsTRUMPF Werkzeugmaschinen SE + Co. KG · TruTops FabTRUMPF Werkzeugmaschinen SE + Co. KG · TruTops Monitor