Summary
A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
Impact
Successful exploitation may allow unauthorized activation of the debug interface and subsequent remote use of the iDTM, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| FDI Package library | vers:generic/>=V1.00.00|<V2.01.00 |
Vulnerabilities
Expand / Collapse allA vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.
Mitigation
If an immediate update is not possible, Endress+Hauser recommends the following measures to reduce the risk of exploitation:
* Restrict access to affected systems to authorized personnel only
* Apply the principle of least privilege and limit administrative access to trusted users.
* Protect application installation directories against unauthorized modification through appropriate operating system access controls.
Following these recommendations reduces the risk of unauthorized activation.
Remediation
Endress+Hauser provides an updated version of FDI Package library V2.02.00 that addresses this vulnerability. Endress+Hauser strongly recommends that customers update to the latest fixed version. For support, please contact your local service center.
Acknowledgments
Endress+Hauser AG thanks the following parties for their efforts:
- CERT@VDE for coordination
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 08/03/2026 09:00 | Initial revision |