{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/asset-administration-shell/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-94293"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Asset Administration Shell"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-94293 represents a critical security flaw in the Asset Administration Shell (AAS) interface, carrying a CVSS v3.1 base score of 9.8. This vulnerability allows an unauthenticated remote attacker to interact with the AAS API without sufficient authorization checks. Specifically, attackers can issue malicious PATCH requests to modify submodel data, potentially leading to system misconfiguration, integrity compromise, or the injection of fraudulent asset data. Furthermore, the vulnerability permits unauthorized GET requests to retrieve all data exposed via the interface, leading to the exfiltration of sensitive asset information. Because the vulnerability does not require authentication, it is highly accessible to any network-adjacent attacker capable of reaching the management API endpoints.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing or internal network-accessible Asset Administration Shell endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the discovery or root API endpoint to map available submodel resources.\u003c/li\u003e\n\u003cli\u003eAttacker sends unauthenticated GET requests to target endpoints to enumerate sensitive system data and submodel configurations.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a target submodel resource for modification.\u003c/li\u003e\n\u003cli\u003eAttacker constructs and sends a crafted PATCH request to the identified submodel URI.\u003c/li\u003e\n\u003cli\u003eThe AAS application processes the unauthenticated PATCH request, applying unauthorized changes to the submodel data.\u003c/li\u003e\n\u003cli\u003eAttacker repeats the process to achieve broader control or to maintain persistence through malicious configuration changes.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the full compromise of data integrity within the Asset Administration Shell, exposing sensitive operational data and allowing unauthorized modification of asset management parameters. This can result in the loss of data confidentiality, the corruption of asset records, and the disruption of industrial or manufacturing processes managed by the AAS.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all instances of Asset Administration Shell within the environment. Ensure that access to the AAS API is restricted via network-level controls such as firewalls or internal network segmentation to block unauthenticated access from unauthorized segments. Monitor web server logs for anomalous patterns of PATCH requests or high volumes of GET requests targeting the AAS API endpoints.\u003c/p\u003e\n\u003ch2 id=\"rules\"\u003eRules\u003c/h2\u003e\n\u003cp\u003etitle: \u0026quot;Detects CVE-2026-94293 Exploitation - Unauthorized PATCH or GET Requests to AAS API\u0026quot;\ndescription: \u0026quot;Detects unauthorized access attempts to the Asset Administration Shell API via PATCH or GET requests from unauthenticated or suspicious sources.\u0026quot;\nlogsource:\ncategory: \u0026quot;webserver\u0026quot;\ndetection:\nselection:\ncs-uri-stem|contains: \u0026quot;/submodel\u0026quot;\ncs-method|in:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u0026quot;GET\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;PATCH\u0026quot;\nfilter:\nsc-status|startswith: \u0026quot;4\u0026quot;\ncondition: selection and not filter\nlevel: \u0026quot;critical\u0026quot;\ntags:\u003c/li\u003e\n\u003cli\u003e\u0026quot;attack.initial_access\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;attack.exfiltration\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;attack.t1190\u0026quot;\ntests:\npositive:\u003c/li\u003e\n\u003cli\u003ename: \u0026quot;Successful PATCH request to submodel endpoint\u0026quot;\ndata:\u003c/li\u003e\n\u003cli\u003ecs-method: \u0026quot;PATCH\u0026quot;\ncs-uri-stem: \u0026quot;/submodel/data/1\u0026quot;\nsc-status: \u0026quot;200\u0026quot;\nnegative:\u003c/li\u003e\n\u003cli\u003ename: \u0026quot;Blocked request to submodel endpoint\u0026quot;\ndata:\u003c/li\u003e\n\u003cli\u003ecs-method: \u0026quot;GET\u0026quot;\ncs-uri-stem: \u0026quot;/submodel/data/1\u0026quot;\nsc-status: \u0026quot;403\u0026quot;\nfalsepositives:\u003c/li\u003e\n\u003cli\u003e\u0026quot;Legitimate administrative tools or authorized API integrations interacting with the AAS API.\u0026quot;\nhandoff:\ndetection_confidence: \u0026quot;medium\u0026quot;\nrequired_telemetry:\u003c/li\u003e\n\u003cli\u003elog_source: \u0026quot;webserver\u0026quot;\nevent_or_channel: \u0026quot;HTTP access logs\u0026quot;\nrequired_fields:\u003c/li\u003e\n\u003cli\u003e\u0026quot;cs-method\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;cs-uri-stem\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;sc-status\u0026quot;\navailability: \u0026quot;available\u0026quot;\nnotes: \u0026quot;Requires web server access logs with full URI and method visibility.\u0026quot;\nvalidation:\nstatus: \u0026quot;needs_environment_validation\u0026quot;\nsteps:\u003c/li\u003e\n\u003cli\u003e\u0026quot;Check baseline traffic volume to AAS endpoints to minimize noise.\u0026quot;\nexpected_telemetry: \u0026quot;Web server access logs showing successful 200 or 204 status codes for PATCH/GET requests.\u0026quot;\npass_criteria: \u0026quot;Detection triggers on requests to AAS submodel endpoints.\u0026quot;\nknown_evasions:\u003c/li\u003e\n\u003cli\u003e\u0026quot;Traffic obfuscation via encrypted tunnels or proxies.\u0026quot;\nlimitations:\u003c/li\u003e\n\u003cli\u003e\u0026quot;Does not distinguish between legitimate and malicious authorized users; requires baseline tuning.\u0026quot;\ntuning:\u003c/li\u003e\n\u003cli\u003esource: \u0026quot;Monitoring/Management tools\u0026quot;\nguidance: \u0026quot;Allowlist known internal source IPs of management tools.\u0026quot;\nportability_notes:\u003c/li\u003e\n\u003cli\u003eplatform: \u0026quot;Splunk|Elastic|Sentinel\u0026quot;\nnote: \u0026quot;Ensure field mapping of standard IIS/Nginx logs to webserver schema.\u0026quot;\nsuggested_owner: \u0026quot;Detection Engineering\u0026quot;\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T08:53:43Z","date_published":"2026-10-06T08:53:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-94293/","summary":"An unauthenticated remote attacker can exploit CVE-2026-94293 to perform unauthorized modifications to submodel data and exfiltrate sensitive information via the Asset Administration Shell.","title":"Critical Unauthorized Access in Asset Administration Shell via CVE-2026-94293","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-94293/"}],"language":"en","title":"CraftedSignal Threat Feed - Asset Administration Shell","version":"https://jsonfeed.org/version/1.1"}