CVE-2022-3575

Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using the configuration upload function. This could lead to a complete compromise of the FDS102 device.
References
Link Resource
https://www.frauscher.com/en/psirt Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.8.0:*:*:*:*:fadc_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.8.0:*:*:*:*:fadci_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.0:*:*:*:*:fadc_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.0:*:*:*:*:fadci_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.1:*:*:*:*:fadc_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.1:*:*:*:*:fadci_r2:*:*

History

05 Nov 2022, 00:30

Type Values Removed Values Added
References (CONFIRM) https://www.frauscher.com/en/psirtĀ - (CONFIRM) https://www.frauscher.com/en/psirtĀ - Vendor Advisory
CPE cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.1:*:*:*:*:fadci_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.8.0:*:*:*:*:fadci_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.0:*:*:*:*:fadc_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.0:*:*:*:*:fadci_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.8.0:*:*:*:*:fadc_r2:*:*
cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.1:*:*:*:*:fadc_r2:*:*

02 Nov 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-02 17:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-3575

Mitre link : CVE-2022-3575

CVE.ORG link : CVE-2022-3575


JSON object : View

Products Affected

frauscher

  • frauscher_diagnostic_system_102
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type