Impact
A local attacker who has elevated privileges on the host system can place a specially crafted file into the application directory of the iDTM FDI package library, causing the debug interface to be enabled. This allows the attacker to access or modify connected devices, potentially exposing sensitive data, altering device behavior, or disrupting device operations. The flaw directly grants unauthorized access to device functionality and data integrity.
Affected Systems
The vulnerability affects Endress+Hauser FDI Package Library. No specific version numbers are listed in the CNA data, so any deployment of the FDI package library with the described file placement capability is potentially impacted. The issue arises when the application directory is writable by privileged users.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. EPSS is not available, and the vulnerability is not in the CISA KEV catalog. The attack requires a user with elevated privileges to write to the application directory, implying a local attack vector. Once the crafted file is detected, the debug interface is activated, providing further control over connected devices. No public exploit is known, but the high severity and local privilege requirement suggest that the risk is significant for environments with limited user separation and where the FDI package library is actively used.
OpenCVE Enrichment