Impact
An unauthenticated remote attacker can retrieve sensitive files from the FDS 102 web server without authentication. The flaw permits direct HTTP download of the backup archive located at /FdsBackup.zip and arbitrary files within /downloads/. These files contain detailed railway signaling and track layout data that should remain confidential, creating a breach of operational secrecy.
Affected Systems
Frauscher Sensortechnik’s FDS 102 product is affected. All released versions of FDS 102 exhibit the unauthenticated file download flaw, as no version constraints are specified in the advisory.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. Although the EPSS score is below 1 %, the flaw requires no authentication or special configuration, making exploitation trivial. It is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request to the exposed endpoints, enabling an attacker to retrieve confidential files directly.
OpenCVE Enrichment