An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-108/ |
|
History
Tue, 06 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints. | |
| Title | Missing authentication for critical function in the aas-edge-client REST API | |
| First Time appeared |
Murrelektronik
Murrelektronik aas Edge Client |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:murrelektronik:aas_edge_client:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Murrelektronik
Murrelektronik aas Edge Client |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-10-06T06:38:04.271Z
Reserved: 2026-09-21T09:39:23.739Z
Link: CVE-2026-94293
No data.
Status : Deferred
Published: 2026-10-06T07:17:00.193
Modified: 2026-10-06T16:08:43.180
Link: CVE-2026-94293
No data.
OpenCVE Enrichment
Updated: 2026-10-06T08:45:16Z
Weaknesses