{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      },
      {
        "names": [
          "Adrien Rey"
        ],
        "organization": "Cyber Defense Campus Zurich",
        "summary": "reporting",
        "urls": [
          "https://www.cydcampus.admin.ch"
        ]
      },
      {
        "names": [
          "Daniel Hulliger"
        ],
        "organization": "Armasuisse",
        "summary": "reporting",
        "urls": [
          "https://www.ar.admin.ch"
        ]
      }
    ],
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "The MBS Universal Gateways (UGW-A-Series, UGW-X-Series) connect devices using various digital communication protocols within the field of building automation. Several security vulnerabilities have been identified in the UGW web GUI and the underlying firmware, affecting version V6_0_0_5 and earlier.\n\nAmong other things, several CGI methods are affected by insufficient input validation and a lack of bounds checking. These flaws allow authorized attackers to perform arbitrary file deletion, include local files, or terminate system processes. Furthermore, multiple stack-based buffer overflows were discovered that can be exploited to execute arbitrary code with root privileges, leading to a full system compromise. Additionally, the firmware contains a hardcoded default password for a service account, which significantly lowers the barrier for unauthorized access.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "Exploitation of these vulnerabilities may allow an authenticated attacker to read or delete arbitrary local files on the affected UGW devices, terminate system processes, or gain unauthorized access through a known service account password. Most significantly, stack-based buffer overflows in several CGI endpoints can be leveraged to execute arbitrary code with root privileges, potentially resulting in a full system compromise. In addition, these flaws can be abused to cause a denial of service or to access confidential configuration data.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "Update the affected products to firmware version V6_0_0_7.\n\nThese are available at https://en.mbs-solutions.de/firmwareupdate",
        "title": "Remediation"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@mbs-solutions.de",
      "name": "MBS GmbH",
      "namespace": "https://www.mbs-solutions.de"
    },
    "references": [
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for MBS GmbH",
        "url": "https://www.certvde.com/en/advisories/vendor/mbs"
      },
      {
        "category": "self",
        "summary": "VDE-2026-039: MBS: Several security vulnerabilities in the UGW web GUI - HTML",
        "url": "https://www.certvde.com/en/advisories/VDE-2026-039/"
      },
      {
        "category": "self",
        "summary": "VDE-2026-039: MBS: Several security vulnerabilities in the UGW web GUI - CSAF",
        "url": "https://mbs.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-039.json"
      }
    ],
    "title": "MBS: Several security vulnerabilities in the UGW web GUI",
    "tracking": {
      "aliases": [
        "VDE-2026-039"
      ],
      "current_release_date": "2026-06-03T13:00:00.000Z",
      "generator": {
        "date": "2026-06-03T13:00:00.000Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.5.44"
        }
      },
      "id": "VDE-2026-039",
      "initial_release_date": "2026-06-03T13:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-06-03T13:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial revision."
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_name",
                    "name": "Single-A",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-A-Series Single-A",
                      "product_id": "CSAFPID-11001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:single_a:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-A Profibus",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-A-Series Double-A Profibus",
                      "product_id": "CSAFPID-11002",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_a_profibus:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-A x-link",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-A-Series Double-A x-link",
                      "product_id": "CSAFPID-11003",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_a_x_link:*:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "UGW-A-Series"
              },
              {
                "branches": [
                  {
                    "category": "product_name",
                    "name": "Single-X",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Single-X",
                      "product_id": "CSAFPID-11004",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:single_x:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-X CAN",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Double-X CAN",
                      "product_id": "CSAFPID-11005",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_x_can:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-X DALI",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Double-X DALI",
                      "product_id": "CSAFPID-11006",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_x_dali:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-X KNX",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Double-X KNX",
                      "product_id": "CSAFPID-11007",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_x_knx:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-X LON",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Double-X LON",
                      "product_id": "CSAFPID-11008",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_x_lon:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-X M-Bus",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Double-X M-Bus",
                      "product_id": "CSAFPID-11009",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_x_m_bus:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-X PROFINET",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Double-X PROFINET",
                      "product_id": "CSAFPID-11010",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_x_profinet:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Double-X x-link",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Double-X x-link",
                      "product_id": "CSAFPID-11011",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:double_x_x_link:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Triple-X KNX+DALI",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Triple-X KNX+DALI",
                      "product_id": "CSAFPID-11012",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:triple_x_knx_dali:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Triple-X KNX+LON",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Triple-X KNX+LON",
                      "product_id": "CSAFPID-11013",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:triple_x_knx_lon:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Triple-X KNX+M-Bus",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Triple-X KNX+M-Bus",
                      "product_id": "CSAFPID-11014",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:triple_x_knx_m_bus:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Triple-X PROFINET+DALI",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Triple-X PROFINET+DALI",
                      "product_id": "CSAFPID-11015",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:triple_x_profinet_dali:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Triple-X PROFINET+KNX",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Triple-X PROFINET+KNX",
                      "product_id": "CSAFPID-11016",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:triple_x_profinet_knx:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Triple-X PROFINET+LON",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Triple-X PROFINET+LON",
                      "product_id": "CSAFPID-11017",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:triple_x_profinet_lon:*:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_name",
                    "name": "Triple-X PROFINET+M-Bus",
                    "product": {
                      "name": "MBS GmbH Hardware UGW-X-Series Triple-X PROFINET+M-Bus",
                      "product_id": "CSAFPID-11018",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:mbs:triple_x_profinet_m_bus:*:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_family",
                "name": "UGW-X-Series"
              }
            ],
            "category": "product_family",
            "name": "Hardware"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:generic/>=V1_0_0_0|<V6_0_0_7",
                "product": {
                  "name": "MBS Firmware <V6_0_0_7",
                  "product_id": "CSAFPID-21001",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:mbs:ugw_firmware:*:*:*:*:*:*:*:*"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "V6_0_0_7",
                "product": {
                  "name": "MBS Firmware V6_0_0_7",
                  "product_id": "CSAFPID-22001",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:mbs:ugw_firmware:V6_0_0_7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Firmware"
          }
        ],
        "category": "vendor",
        "name": "MBS GmbH"
      }
    ],
    "product_groups": [
      {
        "group_id": "CSAFGID-0001",
        "product_ids": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ],
        "summary": "Affected Products"
      },
      {
        "group_id": "CSAFGID-0002",
        "product_ids": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "summary": "Fixed Products."
      }
    ],
    "relationships": [
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-A-Series Single-A",
          "product_id": "CSAFPID-31001",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:single_a_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11001"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-A-Series Double-A Profibus",
          "product_id": "CSAFPID-31002",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_a_profibus_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11002"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-A-Series Double-A x-link",
          "product_id": "CSAFPID-31003",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_a_x_link_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11003"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Single-X",
          "product_id": "CSAFPID-31004",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:single_x_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11004"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Double-X CAN",
          "product_id": "CSAFPID-31005",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_can_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11005"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Double-X DALI",
          "product_id": "CSAFPID-31006",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_dali_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11006"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Double-X KNX",
          "product_id": "CSAFPID-31007",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_knx_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11007"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Double-X LON",
          "product_id": "CSAFPID-31008",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_lon_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11008"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Double-X M-Bus",
          "product_id": "CSAFPID-31009",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_m_bus_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11009"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Double-X PROFINET",
          "product_id": "CSAFPID-31010",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_profinet_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11010"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Double-X x-link",
          "product_id": "CSAFPID-31011",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_x_link_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11011"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Triple-X KNX+DALI",
          "product_id": "CSAFPID-31012",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_knx_dali_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11012"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Triple-X KNX+LON",
          "product_id": "CSAFPID-31013",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_knx_lon_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11013"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Triple-X KNX+M-Bus",
          "product_id": "CSAFPID-31014",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_knx_m_bus_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11014"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Triple-X PROFINET+DALI",
          "product_id": "CSAFPID-31015",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_profinet_dali_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11015"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Triple-X PROFINET+KNX",
          "product_id": "CSAFPID-31016",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_profinet_knx_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11016"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Triple-X PROFINET+LON",
          "product_id": "CSAFPID-31017",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_profinet_lon_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11017"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware <V6_0_0_7 installed on UGW-X-Series Triple-X PROFINET+M-Bus",
          "product_id": "CSAFPID-31018",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_profinet_m_bus_firmware:*:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11018"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-A-Series Single-A",
          "product_id": "CSAFPID-32001",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:single_a_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11001"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-A-Series Double-A Profibus",
          "product_id": "CSAFPID-32002",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_a_profibus_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11002"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-A-Series Double-A x-link",
          "product_id": "CSAFPID-32003",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_a_x_link_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11003"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Single-X",
          "product_id": "CSAFPID-32004",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:single_x_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11004"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Double-X CAN",
          "product_id": "CSAFPID-32005",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_can_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11005"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Double-X DALI",
          "product_id": "CSAFPID-32006",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_dali_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11006"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Double-X KNX",
          "product_id": "CSAFPID-32007",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_knx_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11007"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Double-X LON",
          "product_id": "CSAFPID-32008",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_lon_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11008"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Double-X M-Bus",
          "product_id": "CSAFPID-32009",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_m_bus_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11009"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Double-X PROFINET",
          "product_id": "CSAFPID-32010",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_profinet_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11010"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Double-X x-link",
          "product_id": "CSAFPID-32011",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:double_x_x_link_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11011"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Triple-X KNX+DALI",
          "product_id": "CSAFPID-32012",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_knx_dali_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11012"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Triple-X KNX+LON",
          "product_id": "CSAFPID-32013",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_knx_lon_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11013"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Triple-X KNX+M-Bus",
          "product_id": "CSAFPID-32014",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_knx_m_bus_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11014"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Triple-X PROFINET+DALI",
          "product_id": "CSAFPID-32015",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_profinet_dali_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11015"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Triple-X PROFINET+KNX",
          "product_id": "CSAFPID-32016",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_profinet_knx_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11016"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Triple-X PROFINET+LON",
          "product_id": "CSAFPID-32017",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_profinet_lon_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11017"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "Firmware V6_0_0_7 installed on UGW-X-Series Triple-X PROFINET+M-Bus",
          "product_id": "CSAFPID-32018",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:mbs:triple_x_profinet_m_bus_firmware:V6_0_0_7:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22001",
        "relates_to_product_reference": "CSAFPID-11018"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-35075",
      "cwe": {
        "id": "CWE-1393",
        "name": "Use of Default Password"
      },
      "notes": [
        {
          "category": "description",
          "text": "An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. ",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "Enabling SSH through the device web interface immediately exposes the service account with this known password.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 9.3 / Critical",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Hardcoded default Password for Service Account"
    },
    {
      "cve": "CVE-2026-35076",
      "cwe": {
        "id": "CWE-73",
        "name": "External Control of File Name or Path"
      },
      "notes": [
        {
          "category": "description",
          "text": "The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can delete arbitrary local files, resulting in a loss of system integrity and potential denial of service.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N - 7.2 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Arbitrary file delete vulnerability in method bac-scanresult"
    },
    {
      "cve": "CVE-2026-35077",
      "cwe": {
        "id": "CWE-73",
        "name": "External Control of File Name or Path"
      },
      "notes": [
        {
          "category": "description",
          "text": "The ugw-delete-file method allows a remote attacker with user privileges  to delete arbitrary local files due to insufficient validation of user-controlled input.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can delete arbitrary local files, resulting in loss of system integrity and potential denial of service.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N - 7.2 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Arbitrary file delete vulnerability in method ugw-delete-file"
    },
    {
      "cve": "CVE-2026-35078",
      "cwe": {
        "id": "CWE-73",
        "name": "External Control of File Name or Path"
      },
      "notes": [
        {
          "category": "description",
          "text": "The ugw-logstop method allows a remote attacker with user privileges  to delete arbitrary local files due to insufficient validation of user-controlled input.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can delete arbitrary local files, resulting in loss of system integrity and potential denial of service.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N - 7.2 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Arbitrary file delete vulnerability in method ugw-logstop"
    },
    {
      "cve": "CVE-2026-35079",
      "cwe": {
        "id": "CWE-73",
        "name": "External Control of File Name or Path"
      },
      "notes": [
        {
          "category": "description",
          "text": "The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can delete arbitrary local files with root privileges, resulting in complete loss of system integrity and potential denial of service.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N - 7.2 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Arbitrary file delete vulnerability in method ugw-restore"
    },
    {
      "cve": "CVE-2026-35080",
      "cwe": {
        "id": "CWE-73",
        "name": "External Control of File Name or Path"
      },
      "notes": [
        {
          "category": "description",
          "text": "The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can delete arbitrary local files with root privileges, resulting in complete loss of system integrity and potential denial of service.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N - 7.2 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Arbitrary file delete vulnerability in method ugw-restoreinfo"
    },
    {
      "cve": "CVE-2026-35081",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can terminate arbitrary processes with root privileges, resulting in denial of service and disruption of system functionality.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N - 7.2 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Arbitrary process termination vulnerability in method ugw-logstop"
    },
    {
      "cve": "CVE-2026-35082",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input. ",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can read and subsequently write arbitrary local files, resulting in loss of confidentiality, integrity, and availability.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.7 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Local file inclusion vulnerability and deletion in ugw-logread method"
    },
    {
      "cve": "CVE-2026-35083",
      "cwe": {
        "id": "CWE-121",
        "name": "Stack-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can execute arbitrary code with root privileges, leading to full system compromise.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.7 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Stack buffer overflow in method bac-deviceobject"
    },
    {
      "cve": "CVE-2026-35084",
      "cwe": {
        "id": "CWE-121",
        "name": "Stack-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can execute arbitrary code with root privileges, leading to full system compromise.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.7 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Stack buffer overflow in method dali-devconfig"
    },
    {
      "cve": "CVE-2026-35085",
      "cwe": {
        "id": "CWE-121",
        "name": "Stack-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.",
          "title": "CVE Description"
        },
        {
          "category": "details",
          "text": "An attacker can execute arbitrary code with root privileges, leading to full system compromise.",
          "title": "Impact"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004",
          "CSAFPID-32005",
          "CSAFPID-32006",
          "CSAFPID-32007",
          "CSAFPID-32008",
          "CSAFPID-32009",
          "CSAFPID-32010",
          "CSAFPID-32011",
          "CSAFPID-32012",
          "CSAFPID-32013",
          "CSAFPID-32014",
          "CSAFPID-32015",
          "CSAFPID-32016",
          "CSAFPID-32017",
          "CSAFPID-32018"
        ],
        "known_affected": [
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013",
          "CSAFPID-31014",
          "CSAFPID-31015",
          "CSAFPID-31016",
          "CSAFPID-31017",
          "CSAFPID-31018"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.7 / High",
          "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "MBS GmbH has officially released a new UGW firmware version V6_0_0_7 fixing the described vulnerability.\n\nFor more details please check the release notes on our website.",
          "group_ids": [
            "CSAFGID-0001"
          ],
          "url": "https://en.mbs-solutions.de/firmware-update"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013",
            "CSAFPID-31014",
            "CSAFPID-31015",
            "CSAFPID-31016",
            "CSAFPID-31017",
            "CSAFPID-31018"
          ]
        }
      ],
      "title": "Stack buffer overflow in method gdv-serverconfig"
    }
  ]
}