8.1
CVE-2026-35081
- EPSS 0.37%
- Veröffentlicht 03.06.2026 10:40:44
- Zuletzt bearbeitet 08.06.2026 17:17:25
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
Arbitrary process termination vulnerability in method ugw-logstop
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mbs-solutions ≫ Universal Gateway Firmware Version < 6_00_07
Mbs-solutions ≫ Double-a Profibus Version-
Mbs-solutions ≫ Double-a X-link Version-
Mbs-solutions ≫ Double-x Can Version-
Mbs-solutions ≫ Double-x Dali Version-
Mbs-solutions ≫ Double-x Knx Version-
Mbs-solutions ≫ Double-x Lon Version-
Mbs-solutions ≫ Double-x M-bus Version-
Mbs-solutions ≫ Double-x Profinet Version-
Mbs-solutions ≫ Double-x X-link Version-
Mbs-solutions ≫ Single-a Version-
Mbs-solutions ≫ Single-x Version-
Mbs-solutions ≫ Triple-x Knx+dali Version-
Mbs-solutions ≫ Triple-x Knx+lon Version-
Mbs-solutions ≫ Triple-x Knx+m-bus Version-
Mbs-solutions ≫ Triple-x Profinet+dali Version-
Mbs-solutions ≫ Triple-x Profinet+knx Version-
Mbs-solutions ≫ Triple-x Profinet+lon Version-
Mbs-solutions ≫ Triple-x Profinet+m-bus Version-
Mbs-solutions ≫ Double-a X-link Version-
Mbs-solutions ≫ Double-x Can Version-
Mbs-solutions ≫ Double-x Dali Version-
Mbs-solutions ≫ Double-x Knx Version-
Mbs-solutions ≫ Double-x Lon Version-
Mbs-solutions ≫ Double-x M-bus Version-
Mbs-solutions ≫ Double-x Profinet Version-
Mbs-solutions ≫ Double-x X-link Version-
Mbs-solutions ≫ Single-a Version-
Mbs-solutions ≫ Single-x Version-
Mbs-solutions ≫ Triple-x Knx+dali Version-
Mbs-solutions ≫ Triple-x Knx+lon Version-
Mbs-solutions ≫ Triple-x Knx+m-bus Version-
Mbs-solutions ≫ Triple-x Profinet+dali Version-
Mbs-solutions ≫ Triple-x Profinet+knx Version-
Mbs-solutions ≫ Triple-x Profinet+lon Version-
Mbs-solutions ≫ Triple-x Profinet+m-bus Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.286 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
| info@cert.vde.com | 7.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.certvde.com/en/advisories/VDE-2026-039/