{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      }
    ],
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary code on the FDS102 web server, write files to arbitrary server locations, hijack active administrative sessions, create privileged user accounts, perform unauthorized actions, access sensitive railway signalling and track layout information, and enumerate user accounts and privilege levels. The impact depends on the affected version and attacker privileges, but the combined issue set affects confidentiality, integrity, and availability of the FDS102 web interface and underlying system.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS101/FDS-SNMP101/FDS102. This applies for both vulnerabilities.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added. This applies for CVE-2025-3626. ",
        "title": "Mitigation"
      },
      {
        "category": "description",
        "text": "Update to FDS102 v2.14.0",
        "title": "Remediation"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@frauscher.com",
      "name": "Frauscher Sensortechnik GmbH",
      "namespace": "https://www.frauscher.com"
    },
    "references": [
      {
        "category": "external",
        "summary": "Frauscher advisory overview at CERT@VDE",
        "url": "https://certvde.com/de/advisories/vendor/frauscher/"
      },
      {
        "category": "external",
        "summary": "Frauscher PSIRT",
        "url": "https://www.frauscher.com/en/psirt"
      },
      {
        "category": "self",
        "summary": "VDE-2026-078: Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities - HTML",
        "url": "https://certvde.com/en/advisories/VDE-2026-078/"
      },
      {
        "category": "self",
        "summary": "VDE-2026-078: Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities - CSAF",
        "url": "https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-078.json"
      }
    ],
    "title": "Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities",
    "tracking": {
      "aliases": [
        "VDE-2026-078"
      ],
      "current_release_date": "2026-08-20T10:00:00.000Z",
      "generator": {
        "date": "2026-07-20T05:34:25.955Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.4"
        }
      },
      "id": "VDE-2026-078",
      "initial_release_date": "2026-08-20T10:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-08-20T10:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial revision"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "branches": [
                      {
                        "category": "product_version_range",
                        "name": "vers:semver/>=2.0.0|<=2.13.3",
                        "product": {
                          "name": "FDS102 >=2.0.0<=2.13.3",
                          "product_id": "CSAFID-51001",
                          "product_identification_helper": {
                            "cpe": "cpe:2.3:a:frauscher:fds102:*:*:*:*:*:*:*:*"
                          }
                        }
                      },
                      {
                        "category": "product_version_range",
                        "name": "vers:semver/>=2.1.0|<=2.13.3",
                        "product": {
                          "name": "FDS102 >=2.1.0<=2.13.3",
                          "product_id": "CSAFID-51002",
                          "product_identification_helper": {
                            "cpe": "cpe:2.3:a:frauscher:fds102:*:*:*:*:*:*:*:*"
                          }
                        }
                      },
                      {
                        "category": "product_version_range",
                        "name": "vers:semver/>=2.8.0|<=2.13.3",
                        "product": {
                          "name": "FDS102 >=2.8.0<=2.13.3",
                          "product_id": "CSAFID-51003",
                          "product_identification_helper": {
                            "cpe": "cpe:2.3:a:frauscher:fds102:*:*:*:*:*:*:*:*"
                          }
                        }
                      },
                      {
                        "category": "product_version_range",
                        "name": "vers:semver/>=2.11.0|<=2.13.3",
                        "product": {
                          "name": "FDS102 >=2.11.0<=2.13.3",
                          "product_id": "CSAFID-51004",
                          "product_identification_helper": {
                            "cpe": "cpe:2.3:a:frauscher:fds102:*:*:*:*:*:*:*:*"
                          }
                        }
                      },
                      {
                        "category": "product_version_range",
                        "name": "vers:semver/>=2.13.0|<=2.13.3",
                        "product": {
                          "name": "FDS102 >=2.13.0<=2.13.3",
                          "product_id": "CSAFID-51005",
                          "product_identification_helper": {
                            "cpe": "cpe:2.3:a:frauscher:fds102:*:*:*:*:*:*:*:*"
                          }
                        }
                      },
                      {
                        "category": "product_version",
                        "name": "2.14.0",
                        "product": {
                          "name": "FDS102 2.14.0",
                          "product_id": "CSAFID-52001",
                          "product_identification_helper": {
                            "cpe": "cpe:2.3:a:frauscher:fds102:2.14.0:*:*:*:*:*:*:*"
                          }
                        }
                      }
                    ],
                    "category": "product_name",
                    "name": "102"
                  }
                ],
                "category": "product_family",
                "name": "FDS"
              }
            ],
            "category": "product_family",
            "name": "Software"
          }
        ],
        "category": "vendor",
        "name": "Frauscher"
      }
    ],
    "product_groups": [
      {
        "group_id": "CSAFGID-0001",
        "product_ids": [
          "CSAFID-51001",
          "CSAFID-51002",
          "CSAFID-51003",
          "CSAFID-51004",
          "CSAFID-51005"
        ],
        "summary": "Affected Products."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-14946",
      "cwe": {
        "id": "CWE-434",
        "name": "Unrestricted Upload of File with Dangerous Type"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFID-52001"
        ],
        "known_affected": [
          "CSAFID-51003"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.6 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to FDS102 v2.14.0",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFID-51003"
          ]
        }
      ],
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious configuration file."
    },
    {
      "cve": "CVE-2026-14947",
      "cwe": {
        "id": "CWE-24",
        "name": "Path Traversal: '../filedir'"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFID-52001"
        ],
        "known_affected": [
          "CSAFID-51003"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.6 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to FDS102 v2.14.0",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFID-51003"
          ]
        }
      ],
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file"
    },
    {
      "cve": "CVE-2026-14948",
      "cwe": {
        "id": "CWE-532",
        "name": "Insertion of Sensitive Information into Log File"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFID-52001"
        ],
        "known_affected": [
          "CSAFID-51005"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.7 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to FDS102 v2.14.0",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFID-51005"
          ]
        }
      ],
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive Information into Log File via error log archives"
    },
    {
      "cve": "CVE-2026-14949",
      "cwe": {
        "id": "CWE-863",
        "name": "Incorrect Authorization"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFID-52001"
        ],
        "known_affected": [
          "CSAFID-51004"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H - 8.5 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to FDS102 v2.14.0",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFID-51004"
          ]
        }
      ],
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control"
    },
    {
      "cve": "CVE-2026-14950",
      "cwe": {
        "id": "CWE-613",
        "name": "Insufficient Session Expiration"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFID-52001"
        ],
        "known_affected": [
          "CSAFID-51002"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 9.3 / Critical",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to FDS102 v2.14.0",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFID-51002"
          ]
        }
      ],
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic"
    },
    {
      "cve": "CVE-2026-14951",
      "cwe": {
        "id": "CWE-352",
        "name": "Cross-Site Request Forgery (CSRF)"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFID-52001"
        ],
        "known_affected": [
          "CSAFID-51001"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.6 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to FDS102 v2.14.0",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8,
            "temporalSeverity": "HIGH",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFID-51001"
          ]
        }
      ],
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Cross-Site Request Forgery due to missing CSFR protection headers"
    },
    {
      "cve": "CVE-2026-14952",
      "cwe": {
        "id": "CWE-306",
        "name": "Missing Authentication for Critical Function"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFID-52001"
        ],
        "known_affected": [
          "CSAFID-51002"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - 8.7 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to FDS102 v2.14.0",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFID-51002"
          ]
        }
      ],
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authentication"
    },
    {
      "cve": "CVE-2026-14953",
      "cwe": {
        "id": "CWE-425",
        "name": "Direct Request ('Forced Browsing')"
      },
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFID-52001"
        ],
        "known_affected": [
          "CSAFID-51004"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N - 5.3 / Medium",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update to FDS102 v2.14.0",
          "group_ids": [
            "CSAFGID-0001"
          ]
        },
        {
          "category": "mitigation",
          "details": "Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.",
          "group_ids": [
            "CSAFGID-0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 4.3,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 4.3,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFID-51004"
          ]
        }
      ],
      "title": "Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to improper enforcement of role-based access control"
    }
  ]
}