VDE-2026-108

Vulnerability from csaf_murrelektronikgmbh - Published: 2026-10-06 10:00 - Updated: 2026-10-06 10:00
Summary
Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data
Severity
Critical
Notes
Summary: The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for the LNI 4.0 testbed demonstrator. Its REST API is bound to all network interfaces on TCP port 18000, requires no authentication and accepts cross-origin requests from any origin. The reference implementation was never intended for productive use and is no longer maintained. Affected are all aas-edge-client versions.
Impact: An unauthenticated remote attacker, or a malicious web page opened by a user on a network that can reach the device, can read and modify the Asset Administration Shell submodel data of the edge device. Modified data is stored locally and forwarded to the configured central AAS server, so systems consuming that server may receive manipulated device information.
Mitigation: Discontinue the use of the aas-edge-client and remove any existing deployments as well as copies of the source code and container image. The code must not be used in any environment.
Remediation: Murrelektronik GmbH will not provide a fix. The aas-edge-client was a reference implementation created solely for a trade-fair demonstrator and is no longer maintained. All repositories of the Murrelektronik GmbH GitHub organisation have been set to private, and the aas-edge-client repository has additionally been archived.
Disclaimer: This document is provided on an "AS IS" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document or materials linked from the document is at your own risk. Murrelektronik GmbH reserves the right to change or update this document at any time.

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

CWE-306 - Missing Authentication for Critical Function
Affected products
Product Identifier Version Remediation
Murrelektronik Software AAS Edge Client all versions
Murrelektronik / Software / AAS Edge Client
cpe:2.3:a:murrelektronik:aas_edge_client:*:*:*:*:*:*:*:* vers:all/*
Mitigation
No Fix Planned

{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      },
      {
        "names": [
          "kta1kri"
        ],
        "summary": "finding and reporting"
      }
    ],
    "aggregate_severity": {
      "text": "critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for the LNI 4.0 testbed demonstrator. Its REST API is bound to all network interfaces on TCP port 18000, requires no authentication and accepts cross-origin requests from any origin. The reference implementation was never intended for productive use and is no longer maintained. Affected are all aas-edge-client versions.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "An unauthenticated remote attacker, or a malicious web page opened by a user on a network that can reach the device, can read and modify the Asset Administration Shell submodel data of the edge device. Modified data is stored locally and forwarded to the configured central AAS server, so systems consuming that server may receive manipulated device information.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "Discontinue the use of the aas-edge-client and remove any existing deployments as well as copies of the source code and container image. The code must not be used in any environment.",
        "title": "Mitigation"
      },
      {
        "category": "description",
        "text": "Murrelektronik GmbH will not provide a fix. The aas-edge-client was a reference implementation created solely for a trade-fair demonstrator and is no longer maintained. All repositories of the Murrelektronik GmbH GitHub organisation have been set to private, and the aas-edge-client repository has additionally been archived.",
        "title": "Remediation"
      },
      {
        "category": "legal_disclaimer",
        "text": "This document is provided on an \"AS IS\" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document or materials linked from the document is at your own risk. Murrelektronik GmbH reserves the right to change or update this document at any time.",
        "title": "Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@murrelektronik.de",
      "name": "Murrelektronik GmbH",
      "namespace": "https://murrelektronik.com"
    },
    "references": [
      {
        "category": "external",
        "summary": "Murrelektronik Product Security Incident Response (PSIRT) Team",
        "url": "https://my.murrelektronik.com/home/de/services-support/support/PSIRT"
      },
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for Murrelektronik",
        "url": "https://certvde.com/en/advisories/vendor/murrelektronik"
      },
      {
        "category": "self",
        "summary": "VDE-2026-108: Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data - HTML",
        "url": "https://certvde.com/en/advisories/vde-2026-108/"
      },
      {
        "category": "self",
        "summary": "VDE-2026-108: Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data - CSAF",
        "url": "https://murrelektronik.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-108.json"
      }
    ],
    "title": "Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data",
    "tracking": {
      "aliases": [
        "VDE-2026-108"
      ],
      "current_release_date": "2026-10-06T10:00:00.000Z",
      "generator": {
        "date": "2026-10-02T09:28:39.682Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.12"
        }
      },
      "id": "VDE-2026-108",
      "initial_release_date": "2026-10-06T10:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-10-06T10:00:00.000Z",
          "number": "1.0.0",
          "summary": "initial release"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "Murrelektronik Software AAS Edge Client all versions",
                      "product_id": "CSAFPID-F0001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:murrelektronik:aas_edge_client:*:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "AAS Edge Client"
              }
            ],
            "category": "product_family",
            "name": "Software"
          }
        ],
        "category": "vendor",
        "name": "Murrelektronik"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "kta1kri"
          ],
          "summary": "finding and reporting"
        }
      ],
      "cve": "CVE-2026-94293",
      "cwe": {
        "id": "CWE-306",
        "name": "Missing Authentication for Critical Function"
      },
      "discovery_date": "2026-09-18T06:15:00Z",
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-F0001"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 9.3 / Critical",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "Discontinue the use of the aas-edge-client and remove any existing deployments as well as copies of the source code and container image. The code must not be used in any environment.",
          "product_ids": [
            "CSAFPID-F0001"
          ]
        },
        {
          "category": "no_fix_planned",
          "details": "Murrelektronik will not provide a fix. The aas-edge-client was a reference implementation created solely for a trade-fair demonstrator and is no longer maintained. All repositories of the Murrelektronik GitHub organisation have been set to private, and the aas-edge-client repository has additionally been archived.",
          "product_ids": [
            "CSAFPID-F0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-F0001"
          ]
        }
      ],
      "title": "Missing authentication for critical function in the aas-edge-client REST API"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…