{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      }
    ],
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "The cyber security documentation currently describes some of the implemented functions and is thus intended to provide clarity in the functions described here.",
        "title": "General Recommendations"
      },
      {
        "category": "legal_disclaimer",
        "text": "Lenze SE assumes no liability whatsoever for any kind of losses or consequential losses that occur by the distribution and/or use of this document . All information published in this document is provided on good faith by Lenze SE. Insofar as permissible by law, however, none of this information shall establish any guarantee, commitment or liability on the part of Lenze SE. Lenze SE reserves the right to change or update this document at any time.",
        "title": "Disclamer"
      },
      {
        "category": "description",
        "text": "This vulnerability could compromise the confidentiality, integrity, and availability of the product.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "To resolve this security vulnerability, we recommend installing a firmware update.\n\n| Product         | Firmware | Fixed Version |\n| --------------- | -------- | ------------- |\n| Controller c430 | c4xx     | 1.15.2        |\n| c520            | c5xx     | 1.15.2        |\n| c550            | c5xx     | 1.15.2        |\n| i950 GenA       | i950     | 1.15.0        |\n| i950 GenB       | i950     | 2.0.3         |\n",
        "title": "Remediation"
      },
      {
        "category": "description",
        "text": "Check to see if there is an activation file on the SD Card, and delete it. In addition, it is recommended that you protect each access path with appropriate measures, such as physically securing access to the SD Card, authorizing file transfers via PLC Designer (if supported by the respective product), authorizing file transfers via OPC UA (if supported by the respective product), and customizing the key for SFTP access.",
        "title": "Mitigation"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@lenze.com",
      "name": "Lenze SE",
      "namespace": "https://www.lenze.com"
    },
    "references": [
      {
        "category": "external",
        "summary": "Lenze SE has a Product Security Incident Response Team (PSIRT) with its own communication channel. Contact us via https://www.lenze.com/ and the Service and Cyber Security tab.",
        "url": "https://www.lenze.com/en-de/services/cyber-security"
      },
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for Lenze",
        "url": "https://certvde.com/en/advisories/vendor/lenze/"
      },
      {
        "category": "self",
        "summary": "VDE-2026-077: Lenze: Incorrect signature validation in the enable SSH routine - HTML",
        "url": "https://certvde.com/en/advisories/VDE-2026-077/"
      },
      {
        "category": "self",
        "summary": "VDE-2026-077: Lenze: Incorrect signature validation in the enable SSH routine - CSAF",
        "url": "https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-077.json"
      }
    ],
    "title": "Lenze: Incorrect signature validation in the enable SSH routine",
    "tracking": {
      "aliases": [
        "VDE-2026-077"
      ],
      "current_release_date": "2026-07-27T10:00:00.000Z",
      "generator": {
        "date": "2026-07-24T08:14:14.889Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.4"
        }
      },
      "id": "VDE-2026-077",
      "initial_release_date": "2026-07-27T10:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-07-27T10:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial release."
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_name",
                    "name": "c430",
                    "product": {
                      "name": "Controller c430",
                      "product_id": "CSAFPID-13001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:lenze:c430:*:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "c4x0"
              },
              {
                "branches": [
                  {
                    "category": "product_name",
                    "name": "c520",
                    "product": {
                      "name": "Controller c520",
                      "product_id": "CSAFPID-13002",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:lenze:c520:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "c550",
                    "product": {
                      "name": "Controller c550",
                      "product_id": "CSAFPID-13003",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:lenze:c550:*:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "c5x0"
              },
              {
                "branches": [
                  {
                    "category": "product_name",
                    "name": "i950 GenA",
                    "product": {
                      "name": "i950 Servo Inverter GenA",
                      "product_id": "CSAFPID-13004",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:lenze:i950_gena:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "i950 GenB",
                    "product": {
                      "name": "i950 Servo Inverter GenB",
                      "product_id": "CSAFPID-13005",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:lenze:i950_genb:*:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "i9x0"
              }
            ],
            "category": "product_family",
            "name": "Hardware"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:semver/>=1.0.0|<1.15.2",
                    "product": {
                      "name": "Firmware c4x0 <1.15.2",
                      "product_id": "CSAFPID-21001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:lenze:c4xx_firmware:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "1.15.2",
                    "product": {
                      "name": "Firmware c4x0 1.15.3",
                      "product_id": "CSAFPID-22001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:lenze:c4xx_firmware:1.15.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "Firmware c4xx"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:semver/>=1.0.0|<1.15.2",
                    "product": {
                      "name": "Firmware c5x0 <1.15.2",
                      "product_id": "CSAFPID-21002",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:lenze:c5xx_firmware:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "1.15.2",
                    "product": {
                      "name": "Firmware c5x0 1.15.3",
                      "product_id": "CSAFPID-22002",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:lenze:c5xx_firmware:1.15.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "Firmware c5xx"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:semver/>=1.0.0|<1.14.2",
                    "product": {
                      "name": "Firmware i950 <1.14.2",
                      "product_id": "CSAFPID-21003",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "1.15.0",
                    "product": {
                      "name": "Firmware i950 1.14.3",
                      "product_id": "CSAFPID-22003",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:lenze:i950_firmware:1.15.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "vers:semver/>=2.0.0|<2.0.3",
                    "product": {
                      "name": "Firmware i950 <2.0.2",
                      "product_id": "CSAFPID-21004",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "2.0.3",
                    "product": {
                      "name": "Firmware i950 2.0.3",
                      "product_id": "CSAFPID-22004",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:lenze:i950_firmware:2.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "Firmware i950"
              }
            ],
            "category": "product_family",
            "name": "Firmware"
          }
        ],
        "category": "vendor",
        "name": "Lenze"
      }
    ],
    "product_groups": [
      {
        "group_id": "CSAFGID-0001",
        "product_ids": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ],
        "summary": "Affected Products."
      },
      {
        "group_id": "CSAFGID-0002",
        "product_ids": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005"
        ],
        "summary": "Fixed Products."
      }
    ],
    "relationships": [
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware c4xx <1.15.2 installed on Controller c430",
          "product_id": "CSAFPID-31001",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:c4xx_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-13001"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware c4xx 1.15.2 installed on Controller c430",
          "product_id": "CSAFPID-32001",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:c4xx_firmware:1.15.2:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-13001"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware c5xx <1.15.2 installed on Controller c520",
          "product_id": "CSAFPID-31002",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:c5xx_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21002",
        "relates_to_product_reference": "CSAFPID-13002"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware c5xx <1.15.2 installed on c550",
          "product_id": "CSAFPID-31003",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:c5xx_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21002",
        "relates_to_product_reference": "CSAFPID-13003"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware c5xx 1.15.2 installed on c520",
          "product_id": "CSAFPID-32002",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:c5xx_firmware:1.15.2:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22002",
        "relates_to_product_reference": "CSAFPID-13002"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware c5xx 1.15.2 installed on c550",
          "product_id": "CSAFPID-32003",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:c5xx_firmware:1.15.2:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22002",
        "relates_to_product_reference": "CSAFPID-13003"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware i950 <1.14.2 installed on i950 GenA",
          "product_id": "CSAFPID-31004",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21003",
        "relates_to_product_reference": "CSAFPID-13004"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware i950 1.15.0 installed on i950 GenA",
          "product_id": "CSAFPID-32004",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:i950_firmware:1.15.0:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22003",
        "relates_to_product_reference": "CSAFPID-13004"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware i950 <2.0.3 installed on i950 GenB",
          "product_id": "CSAFPID-31005",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21004",
        "relates_to_product_reference": "CSAFPID-13005"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware i950 2.0.3 installed on i950 GenB",
          "product_id": "CSAFPID-32005",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:lenze:i950_firmware:2.0.3:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22004",
        "relates_to_product_reference": "CSAFPID-13005"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-14837",
      "cwe": {
        "id": "CWE-347",
        "name": "Improper Verification of Cryptographic Signature"
      },
      "notes": [
        {
          "category": "description",
          "text": "Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.5 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To resolve this security vulnerability, we recommend installing a firmware update.\n\n| Product         | Firmware | Fixed Version |\n| --------------- | -------- | ------------- |\n| Controller c430 | c4xx     | 1.15.2        |\n| c520            | c5xx     | 1.15.2        |\n| c550            | c5xx     | 1.15.2        |\n| i950 GenA       | i950     | 1.15.0        |\n| i950 GenB       | i950     | 2.0.3         |\n",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Check to see if there is an activation file on the SD Card, and delete it. In addition, it is recommended that you protect each access path with appropriate measures, such as physically securing access to the SD Card, authorizing file transfers via PLC Designer (if supported by the respective product), authorizing file transfers via OPC UA (if supported by the respective product), and customizing the key for SFTP access.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 7.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        }
      ],
      "title": "SSH Enablement Signature Verification Bypass"
    }
  ]
}