Un nuevo aviso de SCI

Imported from official source

Advisory

Cybersecurity Classified by Officially

Lenze VPN Client, versiones 1.0.0 y posteriores, pero anteriores a la 1.4.7, utilizado en combinación con el gateway IoT x500.

CERT@VDE en coordinación con Lenze ha publicado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría permitir a un atacante ejecutar comandos con privilegios de root o SYSTEM y comprometer por completo el equipo en el que se encuentra instalado el cliente VPN.

Actualizar Lenze VPN Client a la versión 1.4.7 o posterior en todos los equipos en los que se encuentre instalado.

El entorno en la nube de Lenze bloquea las conexiones realizadas desde versiones anteriores. Cuando se intenta establecer una conexión utilizando un cliente vulnerable, se muestra un mensaje indicando que es necesaria una versión más reciente.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.incibe.es/node/662580 This address stopped responding when last checked on September 29, 2026. The record below is what Officially captured.

Officially imported this from INCIBE’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
INCIBE — imported from official source
Official source
https://www.incibe.es/rss.xml RSS
Imported
September 24, 2026 11:30
Versions
1 recorded
Identity
662580 at https://www.incibe.es

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.