PT-2026-84121 · Sauter · Building Controller
CVE-2026-78319
·
Published
2026-09-01
·
Updated
2026-09-01
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SAUTER building controller (affected versions not specified)
Description
A service running on the affected products contains a Time-of-Check Time-of-Use (TOCTOU) race condition. TOCTOU is a software bug where a program checks the state of a resource and then acts on that resource, but the state changes between the check and the use. An unauthenticated remote attacker could exploit this flaw to bypass security controls, potentially resulting in remote code execution.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Building Controller