Home

Description

The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration.

PUBLISHED Reserved 2026-06-08 | Published 2026-06-12 | Updated 2026-06-12 | Assigner icscert




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

All
affected

Default status
unaffected

All
affected

Default status
unaffected

All
affected

Default status
unaffected

All
affected

Credits

Temuri Takalandze reported this vulnerability to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-26-162-02

github.com/...p/csaf_files/OT/white/2026/icsa-26-162-02.json

cve.org (CVE-2026-50244)

nvd.nist.gov (CVE-2026-50244)

Download JSON