{
    "document": {
        "acknowledgments": [
            {
                "organization": "CERT@VDE",
                "summary": "coordination",
                "urls": [
                    "https://certvde.com"
                ]
            },
            {
                "organization": "M&M Software GmbH",
                "summary": "reporting."
            }
        ],
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE",
                "url": "https://www.first.org/tlp/"
            }
        },
        "lang": "en-US",
        "notes": [
            {
                "category": "summary",
                "text": "The fdtCONTAINER component is integrated into an application (host application). The fdtCONTAINER application is a specific host application which integrates the fdtCONTAINER component.\n\nThe fdtCONTAINER component exchanges binary data blobs with such a host application. Typically, the host application saves these binary data blobs into a project storage (project file or a project database).\n\nTo manipulate the data inside the project storage, the attacker needs write access to this project storage. Additionally, the manipulated project needs to be opened by the host application. It depends on the host application whether opening the project requires a user action or not. In\nfdtCONTAINER applications, the user has to open the manipulated project file manually.\n\nIn the case of opening a stored project, the deserialization of the manipulated data can be exploited.",
                "title": "Summary"
            },
            {
                "category": "description",
                "text": "The engineering workstation, on which the host application is executed, might execute malicious code with the user rights of the host application.",
                "title": "Impact"
            },
            {
                "category": "description",
                "text": "1. Exchange project data only via secure exchange services\n2. Use appropriate means to protect the project storage from unauthorized manipulation\n3. Do not open project data from an unknown source\n4. Reduce the user rights of the host application to the necessary minimum",
                "title": "Mitigation"
            },
            {
                "category": "description",
                "title": "Remediation",
                "text": "Planned for future versions"
            }
        ],
        "publisher": {
            "category": "vendor",
            "contact_details": "psirt@endress.com",
            "name": "Endress+Hauser AG",
            "namespace": "https://www.endress.com"
        },
        "references": [
            {
                "category": "external",
                "summary": "Endress+Hauser advisory overview at CERT@VDE",
                "url": "https://certvde.com/de/advisories/vendor/endress+hauser/"
            },
            {
                "category": "self",
                "summary": "VDE-2021-005: Endress+Hauser: Multiple Devices affected by fdtContainer vulnerability - HTML",
                "url": "https://certvde.com/en/advisories/VDE-2021-005"
            },
            {
                "summary": "VDE-2021-005: Endress+Hauser: Multiple Devices affected by fdtContainer vulnerability - CSAF",
                "url": "https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-005.json",
                "category": "self"
            }
        ],
        "title": "Endress+Hauser: Multiple Devices affected by fdtContainer vulnerability",
        "tracking": {
            "aliases": [
                "VDE-2021-005"
            ],
            "current_release_date": "2025-05-14T13:00:14.000Z",
            "generator": {
                "date": "2025-03-12T10:58:11.003Z",
                "engine": {
                    "name": "Secvisogram",
                    "version": "2.5.20"
                }
            },
            "id": "VDE-2021-005",
            "initial_release_date": "2021-03-01T06:39:00.000Z",
            "revision_history": [
                {
                    "date": "2021-03-01T06:39:00.000Z",
                    "number": "1",
                    "summary": "Initial revision."
                },
                {
                    "number": "2",
                    "summary": "Fix: added distribution",
                    "date": "2025-05-14T13:00:14.000Z"
                }
            ],
            "status": "final",
            "version": "2"
        }
    },
    "product_tree": {
        "product_groups": [
            {
                "group_id": "CSAFGID-0001",
                "summary": "Affected Products.",
                "product_ids": [
                    "CSAFPID-51001",
                    "CSAFPID-51002",
                    "CSAFPID-51003",
                    "CSAFPID-51004"
                ]
            }
        ],
        "branches": [
            {
                "category": "vendor",
                "name": "Endress+Hauser",
                "branches": [
                    {
                        "name": "Software",
                        "category": "product_family",
                        "branches": [
                            {
                                "name": "Asset Health Monitoring (FieldCare SFE500)",
                                "category": "product_name",
                                "branches": [
                                    {
                                        "name": "<=2.15.01",
                                        "category": "product_version_range",
                                        "product": {
                                            "product_identification_helper": {
                                                "model_numbers": [
                                                    "SRP700"
                                                ]
                                            },
                                            "name": "Asset Health Monitoring (FieldCare SFE500) <=2.15.01",
                                            "product_id": "CSAFPID-51001"
                                        }
                                    }
                                ]
                            },
                            {
                                "category": "product_name",
                                "name": "DeviceCare",
                                "branches": [
                                    {
                                        "name": "<=1.07.00",
                                        "category": "product_version_range",
                                        "product": {
                                            "name": "DeviceCare <=1.07.00",
                                            "product_id": "CSAFPID-51002",
                                            "product_identification_helper": {
                                                "model_numbers": [
                                                    "SFE100"
                                                ]
                                            }
                                        }
                                    }
                                ]
                            },
                            {
                                "name": "FieldCare",
                                "category": "product_name",
                                "branches": [
                                    {
                                        "name": "<=2.15.01",
                                        "category": "product_version_range",
                                        "product": {
                                            "product_identification_helper": {
                                                "model_numbers": [
                                                    "SFE500"
                                                ]
                                            },
                                            "name": "FieldCare <=2.15.01",
                                            "product_id": "CSAFPID-51003"
                                        }
                                    }
                                ]
                            },
                            {
                                "name": "Field Xpert",
                                "category": "product_name",
                                "branches": [
                                    {
                                        "name": "<=1.05.00",
                                        "category": "product_version_range",
                                        "product": {
                                            "product_identification_helper": {
                                                "model_numbers": [
                                                    "SMT50",
                                                    "SMT70",
                                                    "SMT77"
                                                ]
                                            },
                                            "name": "Field Xpert <=1.05.00",
                                            "product_id": "CSAFPID-51004"
                                        }
                                    }
                                ]
                            }
                        ]
                    }
                ]
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2020-12525",
            "cwe": {
                "id": "CWE-502",
                "name": "Deserialization of Untrusted Data"
            },
            "product_status": {
                "known_affected": [
                    "CSAFPID-51001",
                    "CSAFPID-51002",
                    "CSAFPID-51003",
                    "CSAFPID-51004"
                ]
            },
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "1. Exchange project data only via secure exchange services\n2. Use appropriate means to protect the project storage from unauthorized manipulation\n3. Do not open project data from an unknown source\n4. Reduce the user rights of the host application to the necessary minimum",
                    "group_ids": [
                        "CSAFGID-0001"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Planned for future versions",
                    "group_ids": [
                        "CSAFGID-0001"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "attackComplexity": "LOW",
                        "attackVector": "LOCAL",
                        "availabilityImpact": "HIGH",
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "HIGH",
                        "environmentalScore": 7.3,
                        "environmentalSeverity": "HIGH",
                        "integrityImpact": "HIGH",
                        "privilegesRequired": "LOW",
                        "scope": "UNCHANGED",
                        "temporalScore": 7.3,
                        "temporalSeverity": "HIGH",
                        "userInteraction": "REQUIRED",
                        "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.0"
                    },
                    "products": [
                        "CSAFPID-51001",
                        "CSAFPID-51002",
                        "CSAFPID-51003",
                        "CSAFPID-51004"
                    ]
                }
            ],
            "title": "CVE-2020-12525",
            "notes": [
                {
                    "category": "description",
                    "text": "M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage."
                }
            ]
        }
    ]
}