S1 · 07/27
2021 ·
KUKA
| Company | KUKA |
| Category | machinery oem |
| Type | cyber |
| Date | 07/27 2021 |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | S1 (near-miss / disclosed vulnerability) |
| Scale | KUKA KR C4 controller product line |
| Confidence | high |
| Verification | Cited source on file; not independently re-verified |
| Source | CISA ICS-CERT |
CISA published ICSA-21-208-01 detailing a critical hard-coded-credentials flaw in KUKA KR C4 controllers (KSS versions prior to 8.7) that could give an attacker full read/write/delete access to sensitive system folders; no known public exploitation, patch issued.