CVE-2026-14948 PUBLISHED

Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive Information into Log File via error log archives

Assigner: CERTVDE
Reserved: 07.07.2026 Published: 20.08.2026 Updated: 20.08.2026

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Frauscher Sensortechnik
Product FDS 102
Versions Default: unaffected
  • affected from 2.13.0 to 2.13.3 (incl.)

References

Problem Types

  • CWE-532 Insertion of Sensitive Information into Log File CWE