CVE-2022-3575
Estado: ModificadaCrítica (9.8)—
Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using the configuration upload function. This could lead to a complete compromise of the FDS102 device.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.76%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-434
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-3575",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-3575",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-05T13:43:41.724498Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "Frauscher Sensortechnik",
"product": "Diagnostic System FDS102",
"versions": [
{
"status": "affected",
"version": "v2.8.0",
"versionType": "custom",
"lessThanOrEqual": "v2.9.1"
}
]
}
]
}
],
"published": "2022-11-02T17:15:18.673",
"references": [
{
"url": "https://www.frauscher.com/en/psirt",
"tags": [
"Vendor Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://www.frauscher.com/en/psirt",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using the configuration upload function. This could lead to a complete compromise of the FDS102 device."
},
{
"lang": "es",
"value": "Frauscher Sensortechnik GmbH FDS102 para FAdC R2 y FAdCi R2 v2.8.0 a v2.9.1 son vulnerables a la carga de códigos maliciosos sin autenticación mediante la función de carga de configuración. Esto podría provocar un compromiso total del dispositivo FDS102."
}
],
"lastModified": "2026-06-17T04:59:46.530",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.8.0:*:*:*:*:fadc_r2:*:*",
"vulnerable": true,
"matchCriteriaId": "F46EB758-1260-40FB-A5D5-87C11CA5964B"
},
{
"criteria": "cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.8.0:*:*:*:*:fadci_r2:*:*",
"vulnerable": true,
"matchCriteriaId": "ADB27623-E59D-4062-90AB-7787624971B2"
},
{
"criteria": "cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.0:*:*:*:*:fadc_r2:*:*",
"vulnerable": true,
"matchCriteriaId": "A66B5545-5CF4-4CD2-93BA-D77D5A889DD6"
},
{
"criteria": "cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.0:*:*:*:*:fadci_r2:*:*",
"vulnerable": true,
"matchCriteriaId": "FC2D7FAF-C89C-49DC-B85A-BD36E4B7B9A6"
},
{
"criteria": "cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.1:*:*:*:*:fadc_r2:*:*",
"vulnerable": true,
"matchCriteriaId": "27810BDA-FED1-48CD-B3D8-6B60C0B9195C"
},
{
"criteria": "cpe:2.3:a:frauscher:frauscher_diagnostic_system_102:2.9.1:*:*:*:*:fadci_r2:*:*",
"vulnerable": true,
"matchCriteriaId": "F32CAEB4-0CCD-463D-AAFE-88AD4FF6D3EB"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "info@cert.vde.com"
}