Impact
A race condition known as a Time‑of‑Check Time‑of‑Use (TOCTOU) exists in a service running on certain Sauter hardware. The flaw allows an unauthenticated attacker to manipulate the timing of file operations, bypassing intended security controls and potentially executing unauthorized code. This vulnerability is identified as CWE‑367, a classic example of a race condition defect that can be exploited to achieve code execution.
Affected Systems
The affected products are Sauter ecoS 504 and ecoS 505, the Sauter modu612‑LC, and the Sauter modu660‑AS and modu680‑AS modules. No specific firmware version numbers are listed, so all revisions of these models that ship with the vulnerable service are potentially impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS coupled with the remote, unauthenticated nature of the attack suggests a high likelihood of exploitation. An attacker could send specially crafted requests to the vulnerable file exchange service over the network to trigger the race condition and gain the ability to execute code without authorization.
OpenCVE Enrichment