{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination"},{"organization":"Cyberdefence Campus Domotics Hackathon 2026","summary":"We would like to express our gratitude to the organisers of the Cyberdefence Campus Domotics Hackathon 2026 for their kind invitation to participate and for their responsible disclosure of vulnerabilities.","urls":["https://www.ar.admin.ch/en/news-cyd-campus-conference-2026-en"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affected controllers.","title":"Summary"},{"category":"description","text":"On ecos504 (EY-RC504F***) and ecos505 (EY-RC505F***) update to firmware version 7.0.0. or newer. \n\nOn modu680-AS (EY6AS80F021), modu660-AS (EY6AS60F011)) and modu612-LC (EY6LC12F011), update to firmware version 4.0.0 or newer.\n\nContact your local SAUTER representative if you need further assistance.","title":"Remediation"},{"category":"description","text":"An attacker who successfully exploits this vulnerability may gain full control of the device, potentially affecting the operation, reliability, and security of connected building automation functions.","title":"Impact"}],"publisher":{"category":"vendor","contact_details":"psirt@sautergroup.com","name":"Sauter AG","namespace":"https://www.sauter-controls.com"},"references":[{"category":"self","summary":"VDE-2026-093: SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution - HTML","url":"https://certvde.com/en/advisories/VDE-2026-093"},{"category":"self","summary":"VDE-2026-093: SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution - CSAF","url":"https://sauter.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-093.json"},{"category":"external","summary":"Cyberdefence Campus Domotics Hackathon 2026","url":"https://www.ar.admin.ch/en/news-cyd-campus-conference-2026-en"},{"category":"external","summary":"Sauter Cybersecurity","url":"https://www.sauter-controls.com/en/cybersecurity/"},{"category":"external","summary":"CERT@VDE Security Advisories for Sauter","url":"https://certvde.com/de/advisories/vendor/sauter"}],"title":"SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution","tracking":{"aliases":["VDE-2026-093"],"current_release_date":"2026-09-01T10:00:00.000Z","generator":{"date":"2026-09-01T06:40:23.164Z","engine":{"name":"Secvisogram","version":"2.6.6"}},"id":"VDE-2026-093","initial_release_date":"2026-09-01T10:00:00.000Z","revision_history":[{"date":"2026-09-01T10:00:00.000Z","number":"1.0.0","summary":"Initial revision"}],"status":"final","version":"1.0.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"7.0.0","product":{"name":"EY-modulo 5 embedded software version 7.0.0","product_id":"CSAFPID-21003","product_identification_helper":{"cpe":"cpe:2.3:o:sauter:ey-modulo_5_embedded_software:7.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"vers:semver/>=1.0.0|<7.0.0","product":{"name":"EY-modulo 5 embedded software version <7.0.0","product_id":"CSAFPID-21004","product_identification_helper":{"cpe":"cpe:2.3:o:sauter:ey-modulo_5_embedded_software:*:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"EY-modulo 5 embedded software"},{"branches":[{"category":"product_version","name":"4.0.0","product":{"name":"modulo 6 embedded software version 4.0.0","product_id":"CSAFPID-21001","product_identification_helper":{"cpe":"cpe:2.3:o:sauter:modulo_6_embedded_software:4.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"vers:semver/>=1.0.0|<4.0.0","product":{"name":"modulo 6 embedded software version <4.0.0","product_id":"CSAFPID-21002","product_identification_helper":{"cpe":"cpe:2.3:o:sauter:ey-modulo_5_embedded_software:*:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"modulo 6 embedded software"}],"category":"product_family","name":"Firmware"},{"branches":[{"branches":[{"category":"product_name","name":"ecos504","product":{"name":"EY-modulo 5 ecos504","product_id":"CSAFPID-11004","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:ecos504:*:*:*:*:*:*:*:*","model_numbers":["EY-RC504F***"]}}},{"category":"product_name","name":"ecos505","product":{"name":"EY-modulo 5 ecos505","product_id":"CSAFPID-11005","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:ecos505:*:*:*:*:*:*:*:*","model_numbers":["EY-RC505F***"]}}}],"category":"product_family","name":"EY-modulo 5"},{"branches":[{"category":"product_name","name":"modu612-LC","product":{"name":"modulo 6 modu612-LC","product_id":"CSAFPID-11003","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu612-lc:*:*:*:*:*:*:*:*","model_numbers":["EY6LC12F011"]}}},{"category":"product_name","name":"modu660-AS","product":{"name":"modulo 6 modu660-AS","product_id":"CSAFPID-11002","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu660-as:*:*:*:*:*:*:*:*","model_numbers":["EY6AS60F011"]}}},{"category":"product_name","name":"modu680-AS","product":{"name":"modulo 6 modu680-AS","product_id":"CSAFPID-11001","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu680-as:*:*:*:*:*:*:*:*","model_numbers":["EY6AS80F021"]}}}],"category":"product_family","name":"modulo 6"}],"category":"product_family","name":"Hardware"}],"category":"vendor","name":"Sauter"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005"],"summary":"Fixed products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"modulo 6 embedded software version 4.0.0 installed on modulo 6 modu680-AS","product_id":"CSAFPID-32001","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu680-as:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"modulo 6 embedded software version 4.0.0 installed on modulo 6 modu660-AS","product_id":"CSAFPID-32002","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu660-as:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"modulo 6 embedded software version 4.0.0 installed on modulo 6 modu612-LC","product_id":"CSAFPID-32003","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu612-lc:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"modulo 6 embedded software version <4.0.0 installed on modulo 6 modu680-AS","product_id":"CSAFPID-31004","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu680-as:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"modulo 6 embedded software version <4.0.0 installed on modulo 6 modu660-AS","product_id":"CSAFPID-31005","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu660-as:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"modulo 6 embedded software version <4.0.0 installed on modulo 6 modu612-LC","product_id":"CSAFPID-31006","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:modu612-lc:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"EY-modulo 5 embedded software version 7.0.0 installed on EY-modulo 5 ecos504","product_id":"CSAFPID-32004","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:ecos504:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21003","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"EY-modulo 5 embedded software version 7.0.0 installed on EY-modulo 5 ecos505","product_id":"CSAFPID-32005","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:ecos505:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21003","relates_to_product_reference":"CSAFPID-11005"},{"category":"installed_on","full_product_name":{"name":"EY-modulo 5 embedded software version <7.0.0 installed on EY-modulo 5 ecos504","product_id":"CSAFPID-31007","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:ecos504:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21004","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"EY-modulo 5 embedded software version <7.0.0 installed on EY-modulo 5 ecos505","product_id":"CSAFPID-31008","product_identification_helper":{"cpe":"cpe:2.3:h:sauter:ecos505:*:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21004","relates_to_product_reference":"CSAFPID-11005"}]},"vulnerabilities":[{"cve":"CVE-2026-78319","cwe":{"id":"CWE-367","name":"Time-of-check Time-of-use (TOCTOU) Race Condition"},"notes":[{"category":"description","text":"A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition.\nAn unauthenticated remote attacker could exploit this race condition to bypass intended security controls.\nThis may result in the execution of unauthorized code.","title":"CVE description"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005"],"known_affected":["CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"]},"references":[{"category":"external","summary":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 9.3 / Critical","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"remediations":[{"category":"mitigation","details":"Protect access to device and network according to best practices and state of the art means.","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"Update modulo 6 affected products with Firmware Version 4.0.0 or higher and enable the downgrade protection.","product_ids":["CSAFPID-31004","CSAFPID-31005","CSAFPID-31006"]},{"category":"vendor_fix","details":"Update EY-modulo 5 affected products with Firmware Version 7.0.0 or higher and enable the downgrade protection.","product_ids":["CSAFPID-31007","CSAFPID-31008"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.8,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.8,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008"]}],"title":"TOCTOU Vulnerability in file exchange"}]}