PatchSiren cyber security CVE debrief
CVE-2026-40623 SenseLive CVE debrief
CVE-2026-40623 affects the SenseLive X3050 V1.523 web management interface. The advisory says sensitive system and network settings can be changed without sufficient validation and safety controls, including IP addressing, watchdog timers, reconnect intervals, and service ports. Because these settings influence core behavior and recovery, unsafe values can destabilize the device or leave it persistently unavailable.
- Vendor
- SenseLive
- Product
- X3050
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-21
- Original CVE updated
- 2026-04-21
- Advisory published
- 2026-04-21
- Advisory updated
- 2026-04-21
Who should care
Operators and administrators of SenseLive X3050 V1.523 devices, especially OT/ICS teams, network and systems administrators, and anyone responsible for access to the device’s web management interface.
Technical summary
According to the CISA CSAF advisory ICSA-26-111-12, the issue has CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H and a base score of 8.1 (High). The web management interface does not adequately enforce constraints on sensitive configuration functions, allowing unsupported or unsafe parameter values to be applied to critical network and recovery settings. The result is integrity and availability impact, with a risk of device instability or persistent unavailability.
Defensive priority
High. This is a remotely reachable management-plane issue with integrity and availability impact on an ICS device, so exposed or widely accessible X3050 management interfaces should be reviewed promptly.
Recommended defensive actions
- Inventory all SenseLive X3050 V1.523 devices and confirm which ones expose the web management interface.
- Restrict access to the management interface to trusted administrative networks and least-privilege users.
- Review and validate current configuration values for IP addressing, watchdog timers, reconnect intervals, and service ports against known-good baselines.
- Back up current configurations and verify recovery procedures so unsafe settings can be rolled back quickly if needed.
- Monitor for unauthorized or unexpected configuration changes on management interfaces and related network services.
- Follow CISA ICS recommended practices and contact SenseLive for product-specific guidance using the vendor contact path provided in the advisory.
Evidence notes
Primary facts come from the CISA CSAF advisory for ICSA-26-111-12, published 2026-04-21, and its referenced CVE record. The supplied advisory text states that the X3050 web management interface can accept unsupported or unsafe values for sensitive settings and that these changes may destabilize the device or render it persistently unavailable. The source also lists CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H, includes an SSVCv2 note of E:N/A:N/2026-04-20T06:00:00.000000Z, and says SenseLive did not respond to CISA’s coordination requests. The supplied data does not include a KEV entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40623 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40623
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40623 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40623
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-12.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.