PT-2023-28635 · Frauscher Sensortechnik Gmbh · Fds101
Published
2023-09-20
·
Updated
2023-09-22
·
CVE-2023-4291
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi versions 1.4.24 and all previous versions
Description
The issue is a remote code execution (RCE) vulnerability that can be exploited via manipulated parameters of the web interface without authentication, potentially leading to a full compromise of the FDS101 device.
Recommendations
For versions 1.4.24 and all previous versions, consider disabling access to the web interface until a patch is available to prevent exploitation of the RCE vulnerability. Restrict access to the device to minimize the risk of compromise. Avoid using manipulated parameters in the web interface to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fds101