Back to overview

Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library

VDE-2026-065
Last update
08/03/2026 09:00
Published at
08/03/2026 09:00
Vendor(s)
Endress+Hauser AG
External ID
VDE-2026-065
CSAF Document

Summary

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.

Impact

Successful exploitation may allow unauthorized activation of the debug interface and subsequent remote use of the iDTM, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.

Affected Product(s)

Model no. Product name Affected versions
FDI Package library vers:generic/>=V1.00.00|<V2.01.00

Vulnerabilities

Expand / Collapse all

Published
08/03/2026 08:30
Weakness
Uncontrolled Search Path Element (CWE-427)
Summary

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.

References

Mitigation

If an immediate update is not possible, Endress+Hauser recommends the following measures to reduce the risk of exploitation:
* Restrict access to affected systems to authorized personnel only
* Apply the principle of least privilege and limit administrative access to trusted users.
* Protect application installation directories against unauthorized modification through appropriate operating system access controls.

Following these recommendations reduces the risk of unauthorized activation.

Remediation

Endress+Hauser provides an updated version of FDI Package library V2.02.00 that addresses this vulnerability. Endress+Hauser strongly recommends that customers update to the latest fixed version. For support, please contact your local service center.

Acknowledgments

Endress+Hauser AG thanks the following parties for their efforts:

  • CERT@VDE for coordination

Revision History

Version Date Summary
1.0.0 08/03/2026 09:00 Initial revision