{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination"
      }
    ],
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "Successful exploitation may allow unauthorized activation of the debug interface and subsequent remote use of the iDTM, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "If an immediate update is not possible, Endress+Hauser recommends the following measures to reduce the risk of exploitation:\n* Restrict access to affected systems to authorized personnel only\n* Apply the principle of least privilege and limit administrative access to trusted users.\n* Protect application installation directories against unauthorized modification through appropriate operating system access controls.\n\nFollowing these recommendations reduces the risk of unauthorized activation.",
        "title": "Mitigation"
      },
      {
        "category": "description",
        "text": "Endress+Hauser provides an updated version of FDI Package library V2.02.00 that addresses this vulnerability. Endress+Hauser strongly recommends that customers update to the latest fixed version. For support, please contact your local service center.",
        "title": "Remediation"
      },
      {
        "category": "general",
        "text": "Endress+Hauser recommends operating these solutions in a secure environment and restricting access to components to authorized personnel only.",
        "title": "General Recommendation"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@endress.com",
      "name": "Endress+Hauser AG",
      "namespace": "https://www.endress.com"
    },
    "references": [
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for Endress+Hauser",
        "url": "https://certvde.com/de/advisories/vendor/endress-hauser"
      },
      {
        "category": "self",
        "summary": "Endress+Hauser",
        "url": "https://www.endress.com"
      },
      {
        "category": "self",
        "summary": "VDE-2026-065: Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library - HTML",
        "url": "https://certvde.com/en/advisories/VDE-2026-065"
      },
      {
        "category": "self",
        "summary": "VDE-2026-065: Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library - CSAF",
        "url": "https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-065.json"
      }
    ],
    "title": "Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library",
    "tracking": {
      "aliases": [
        "VDE-2026-065"
      ],
      "current_release_date": "2026-08-03T07:00:00.000Z",
      "generator": {
        "date": "2026-08-03T06:24:06.867Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.7"
        }
      },
      "id": "VDE-2026-065",
      "initial_release_date": "2026-08-03T07:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-08-03T07:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial revision"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:generic/>=V1.00.00|<V2.01.00",
                    "product": {
                      "name": "FDI Package library V1.00.00 < V2.01.00",
                      "product_id": "CSAFPID-51001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:endress_hauser:fdi_package_library:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "V2.02.00",
                    "product": {
                      "name": "FDI Package library V2.02.00",
                      "product_id": "CSAFPID-52001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:endress_hauser:fdi_package_library:v2.02.00:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "FDI Package library"
              }
            ],
            "category": "product_family",
            "name": "Software"
          }
        ],
        "category": "vendor",
        "name": "Endress+Hauser"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-9593",
      "cwe": {
        "id": "CWE-427",
        "name": "Uncontrolled Search Path Element"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.\n\n",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-52001"
        ],
        "known_affected": [
          "CSAFPID-51001"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.4 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "If an immediate update is not possible, Endress+Hauser recommends the following measures to reduce the risk of exploitation:\n* Restrict access to affected systems to authorized personnel only\n* Apply the principle of least privilege and limit administrative access to trusted users.\n* Protect application installation directories against unauthorized modification through appropriate operating system access controls.\n\nFollowing these recommendations reduces the risk of unauthorized activation.",
          "product_ids": [
            "CSAFPID-51001"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Endress+Hauser provides an updated version of FDI Package library V2.02.00 that addresses this vulnerability. Endress+Hauser strongly recommends that customers update to the latest fixed version. For support, please contact your local service center.",
          "product_ids": [
            "CSAFPID-51001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.7,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 6.7,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-51001"
          ]
        }
      ],
      "title": "iDTM FDI Unauthorized Debug Interface Enablement"
    }
  ]
}