{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      },
      {
        "names": [
          "kta1kri"
        ],
        "summary": "finding and reporting"
      }
    ],
    "aggregate_severity": {
      "text": "critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for the LNI 4.0 testbed demonstrator. Its REST API is bound to all network interfaces on TCP port 18000, requires no authentication and accepts cross-origin requests from any origin. The reference implementation was never intended for productive use and is no longer maintained. Affected are all aas-edge-client versions.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "An unauthenticated remote attacker, or a malicious web page opened by a user on a network that can reach the device, can read and modify the Asset Administration Shell submodel data of the edge device. Modified data is stored locally and forwarded to the configured central AAS server, so systems consuming that server may receive manipulated device information.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "Discontinue the use of the aas-edge-client and remove any existing deployments as well as copies of the source code and container image. The code must not be used in any environment.",
        "title": "Mitigation"
      },
      {
        "category": "description",
        "text": "Murrelektronik GmbH will not provide a fix. The aas-edge-client was a reference implementation created solely for a trade-fair demonstrator and is no longer maintained. All repositories of the Murrelektronik GmbH GitHub organisation have been set to private, and the aas-edge-client repository has additionally been archived.",
        "title": "Remediation"
      },
      {
        "category": "legal_disclaimer",
        "text": "This document is provided on an \"AS IS\" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document or materials linked from the document is at your own risk. Murrelektronik GmbH reserves the right to change or update this document at any time.",
        "title": "Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@murrelektronik.de",
      "name": "Murrelektronik GmbH",
      "namespace": "https://murrelektronik.com"
    },
    "references": [
      {
        "category": "external",
        "summary": "Murrelektronik Product Security Incident Response (PSIRT) Team",
        "url": "https://my.murrelektronik.com/home/de/services-support/support/PSIRT"
      },
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for Murrelektronik",
        "url": "https://certvde.com/en/advisories/vendor/murrelektronik"
      },
      {
        "category": "self",
        "summary": "VDE-2026-108: Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data - HTML",
        "url": "https://certvde.com/en/advisories/vde-2026-108/"
      },
      {
        "category": "self",
        "summary": "VDE-2026-108: Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data - CSAF",
        "url": "https://murrelektronik.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-108.json"
      }
    ],
    "title": "Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data",
    "tracking": {
      "aliases": [
        "VDE-2026-108"
      ],
      "current_release_date": "2026-10-06T10:00:00.000Z",
      "generator": {
        "date": "2026-10-02T09:28:39.682Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.12"
        }
      },
      "id": "VDE-2026-108",
      "initial_release_date": "2026-10-06T10:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-10-06T10:00:00.000Z",
          "number": "1.0.0",
          "summary": "initial release"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "Murrelektronik Software AAS Edge Client all versions",
                      "product_id": "CSAFPID-F0001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:murrelektronik:aas_edge_client:*:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "AAS Edge Client"
              }
            ],
            "category": "product_family",
            "name": "Software"
          }
        ],
        "category": "vendor",
        "name": "Murrelektronik"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "kta1kri"
          ],
          "summary": "finding and reporting"
        }
      ],
      "cve": "CVE-2026-94293",
      "cwe": {
        "id": "CWE-306",
        "name": "Missing Authentication for Critical Function"
      },
      "discovery_date": "2026-09-18T06:15:00Z",
      "notes": [
        {
          "audience": "all",
          "category": "description",
          "text": "An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-F0001"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 9.3 / Critical",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "Discontinue the use of the aas-edge-client and remove any existing deployments as well as copies of the source code and container image. The code must not be used in any environment.",
          "product_ids": [
            "CSAFPID-F0001"
          ]
        },
        {
          "category": "no_fix_planned",
          "details": "Murrelektronik will not provide a fix. The aas-edge-client was a reference implementation created solely for a trade-fair demonstrator and is no longer maintained. All repositories of the Murrelektronik GitHub organisation have been set to private, and the aas-edge-client repository has additionally been archived.",
          "product_ids": [
            "CSAFPID-F0001"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-F0001"
          ]
        }
      ],
      "title": "Missing authentication for critical function in the aas-edge-client REST API"
    }
  ]
}