Impact
The vulnerability allows a remote attacker with low privileges to enumerate all configured users and identify which accounts hold elevated privileges through the /api/user/fetch-all.php endpoint, due to missing authorization enforcement. This results in an elevation of privilege scenario where the attacker can discover privileged accounts without authenticating as an administrator.
Affected Systems
Frauscher Sensortechnik’s FDS 102 firmware is affected. No specific firmware version is listed in the advisory, so all releases of the FDS 102 product should be considered potentially vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a low‑privileged remote user who accesses the system and can send requests to the endpoint without additional permissions, allowing enumeration of privileged accounts. Because the endpoint is exposed to non‑admin users, an attacker with legitimate but non‑elevated user rights has the potential to gain knowledge of higher‑privilege accounts, which could be leveraged in subsequent attacks.
OpenCVE Enrichment