Kieback & Peter DDC Building Controllers Cross-site Scripting
Summary
| CVE | CVE-2026-4293 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-20 16:16:26 UTC |
| Updated | 2026-05-20 17:30:40 UTC |
| Description | The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.000400000 probability, percentile 0.122720000 (date 2026-05-27)
Problem Types: CWE-79 | CWE-79 CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Kieback Peter | DDC4002 | affected 1.12.14 custom | Not specified |
| CNA | Kieback Peter | DDC4100 | affected 1.12.14 custom | Not specified |
| CNA | Kieback Peter | DDC4200 | affected 1.12.14 custom | Not specified |
| CNA | Kieback Peter | DDC4200-L | affected 1.12.14 custom | Not specified |
| CNA | Kieback Peter | DDC4400 | affected 1.12.14 custom | Not specified |
| CNA | Kieback Peter | DDC4002e | affected 1.23.4 custom | Not specified |
| CNA | Kieback Peter | DDC4200e | affected 1.23.4 custom | Not specified |
| CNA | Kieback Peter | DDC4400e | affected 1.23.4 custom | Not specified |
| CNA | Kieback Peter | DDC4020e | affected 1.23.4 custom | Not specified |
| CNA | Kieback Peter | DDC4040e | affected 1.23.4 custom | Not specified |
| CNA | Kieback Peter | DDC520 | affected 1.24.1 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-13... | [email protected] | github.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-26-139-05 | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Maximilian Hildebrand of G DATA Advanced Analytics reported this vulnerability to CISA. (en)
Additional Advisory Data
Solutions
CNA: For DDC520, DDC4002e, DDC4200e, DDC4400e, DDC4020e, and DDC4040e controllers, update the firmware to the latest available version: * DDC4002e: Update to version 1.23.5 or newer * DDC4200e: Update to version 1.23.5 or newer * DDC4400e: Update to version 1.23.5 or newer * DDC4020e: Update to version 1.23.5 or newer * DDC4040e: Update to version 1.23.5 or newer * DDC520: Update to version 1.24.2 or newer
Workarounds
CNA: Kieback & Peter DDC Building Controllers are developed and designed for use in closed building automation networks. The system is protected by a multi-level perimeter against attacks, especially from outside, by dividing it into operational technology (OT) zones with firewalls. Building automation systems (BA systems) in general should not be directly accessible from untrusted networks, especially from the Internet, but should be protected by consistently applying the defense-in-depth strategy. This concept is supported by organizational measures in the building as part of a safety management system. In order to achieve safety, measures are required at all levels.
CNA: The DDC4002, DDC4100, DDC4200, DDC4200-L and DDC4400 controllers are end-of-maintenance, therefore the recommendations for these devices are as follows: * These devices must be operated in a strictly separate OT environment. * Only trusted individuals should be granted network access to the DDC web portal. * Access to the web portal should be disabled in the device configuration if not required. * Users should be informed that only links from trusted sources should be used to access the web service. * Restrict network access to the device * Do not directly connect the device to the Internet
CNA: For DDC520, DDC4002e, DDC4200e, DDC4400e, DDC4020e, and DDC4040e controllers, Kieback & Peter recommends the following safety measures: * Restrict network access to the device * Do not directly connect the device to the Internet