CVE-2026-14948

8.8

Frauscher · FDS 102

The Frauscher FDS 102 system is vulnerable to session hijacking, as administrative session identifiers are inadvertently stored in plaintext within downloadable error log archives.

Executive summary

A critical information disclosure vulnerability in Frauscher FDS 102 allows low privileged attackers to hijack active administrative sessions.

Vulnerability

This is an information disclosure vulnerability (CWE-532) where sensitive session identifiers are written to log files. A low privileged remote attacker can download these logs to extract active session tokens, bypassing the need for administrative credentials.

Business impact

Successful exploitation results in complete administrative access to the FDS 102 system. This poses a severe risk to operational security, as an attacker could modify system settings or access sensitive industrial data. The CVSS score of 8.8 highlights the high potential for unauthorized access and lateral movement within the network.

Remediation

Immediate Action: Contact the vendor for specific patch availability and apply all recommended security updates to the FDS 102 system.

Proactive Monitoring: Audit access logs for unauthorized attempts to download diagnostic or error files, particularly by low privileged accounts.

Compensating Controls: Restrict access to diagnostic interfaces and error log downloads to authorized personnel only, utilizing network segmentation to isolate the management interface.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

This vulnerability represents a significant security oversight that directly compromises the authentication mechanism. Users must prioritize obtaining and installing the vendor-supplied fix to prevent unauthorized administrative control.