Description
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
Published: 2026-08-20
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low privileged remote attacker can hijack an active administrative session without knowing the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives. The vulnerability stems from improper log handling that discloses sensitive session information, classified as CWE-532.

Affected Systems

Frauscher Sensortechnik FDS 102 is affected by this flaw.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity of this flaw, while the EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. An attacker with low privileges can acquire session identifiers by downloading error logs, enabling session hijacking without additional credentials. No further conditions are noted in the description.

Generated by OpenCVE AI on August 20, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or firmware update for Frauscher Sensortechnik FDS 102 as soon as it is available
  • Reconfigure the system to remove session identifiers from error logs, ensuring that logs do not store sensitive authentication data
  • Restrict access to error log archives so that only authorized administrators can retrieve them

Generated by OpenCVE AI on August 20, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
Title Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive Information into Log File via error log archives
First Time appeared Frauscher Sensortechnik
Frauscher Sensortechnik fds 102
Weaknesses CWE-532
CPEs cpe:2.3:a:frauscher_sensortechnik:fds_102:*:*:*:*:*:*:*:*
Vendors & Products Frauscher Sensortechnik
Frauscher Sensortechnik fds 102
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Frauscher Sensortechnik Fds 102
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-08-20T15:26:27.063Z

Reserved: 2026-07-07T12:46:57.386Z

Link: CVE-2026-14948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T09:16:47.137

Modified: 2026-08-20T16:17:07.080

Link: CVE-2026-14948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:30:05Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File