CVE-2026-78319
9.3Sauter · modu680-AS, modu660-AS, modu612-LC, ecos504, ecos505
A Time-of-Check Time-of-Use race condition in Sauter automation controllers allows unauthenticated remote attackers to bypass security controls and execute unauthorized code.
Executive summary
A critical race condition vulnerability in multiple Sauter building automation controllers enables unauthenticated remote code execution, posing a severe risk to operational infrastructure.
Vulnerability
The vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition (CWE-367) within a service running on the affected devices. An unauthenticated remote attacker can exploit this flaw to bypass security constraints, potentially leading to unauthorized code execution.
Business impact
The CVSS score of 9.3 indicates a critical severity, reflecting the potential for full system compromise by unauthenticated actors. Successful exploitation could lead to unauthorized control over building automation systems, potentially resulting in operational downtime, physical equipment damage, or the exfiltration of sensitive environmental data.
Remediation
Immediate Action: Update the affected Sauter controllers to the version specified in the official vendor advisory (VDE-2026-093) to remediate the underlying race condition.
Proactive Monitoring: Monitor device logs for anomalous service behavior or frequent service restarts that may indicate exploitation attempts against the race condition.
Compensating Controls: Implement strict network segmentation to isolate automation controllers from untrusted networks and utilize industrial firewalls to restrict access to authorized management stations only.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this vulnerability and the ability for unauthenticated remote attackers to achieve code execution, immediate remediation is required. Administrators should prioritize patching all exposed Sauter controllers to the latest available firmware provided by the vendor. Ensure that these devices are not accessible from the public internet to further reduce the attack surface until the updates are successfully deployed.