8.1

CVE-2026-35081

Arbitrary process termination vulnerability in method ugw-logstop

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mbs-solutionsUniversal Gateway Firmware Version < 6_00_07
   Mbs-solutionsDouble-a Profibus Version-
   Mbs-solutionsDouble-a X-link Version-
   Mbs-solutionsDouble-x Can Version-
   Mbs-solutionsDouble-x Dali Version-
   Mbs-solutionsDouble-x Knx Version-
   Mbs-solutionsDouble-x Lon Version-
   Mbs-solutionsDouble-x M-bus Version-
   Mbs-solutionsDouble-x Profinet Version-
   Mbs-solutionsDouble-x X-link Version-
   Mbs-solutionsSingle-a Version-
   Mbs-solutionsSingle-x Version-
   Mbs-solutionsTriple-x Knx+dali Version-
   Mbs-solutionsTriple-x Knx+lon Version-
   Mbs-solutionsTriple-x Knx+m-bus Version-
   Mbs-solutionsTriple-x Profinet+dali Version-
   Mbs-solutionsTriple-x Profinet+knx Version-
   Mbs-solutionsTriple-x Profinet+lon Version-
   Mbs-solutionsTriple-x Profinet+m-bus Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.286
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
info@cert.vde.com 7.2 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.certvde.com/en/advisories/VDE-2026-039/
Vendor Advisory