CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-94293: Software AAS Edge Client all versions 0.0.0

CVE-2026-94293. CVSS 3.1 base score 9.8 (ghsa).

Affected technology

Software AAS Edge Client all versions · 0.0.0
Murrelektronik

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints. Vendor/CNA’s CVSS 4.0 assessment (base score 9.3/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-306
CCR priority
39.2 /100 (P4)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-94293.html