Description
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-076/ |
|
History
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access. | |
| Title | ads-tec Industrial IT: Vertical privilege escalation via configuration table write | |
| First Time appeared |
Ads Tec
Ads Tec irf1000 Firmware Ads Tec irf3000 Firmware |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:o:ads_tec:irf1000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ads_tec:irf3000_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ads Tec
Ads Tec irf1000 Firmware Ads Tec irf3000 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-07-28T12:46:30.943Z
Reserved: 2026-06-30T06:39:05.718Z
Link: CVE-2026-14168
Updated: 2026-07-28T12:46:03.476Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization