CyberRota Analysis
AI-GeneratedAn unauthenticated remote attacker can exploit a vulnerability in the FDS Web server to access sensitive files, including a backup archive and other critical data, via HTTP without requiring a valid session. This exposure of railway signaling and track layout information poses significant risks to operational security and safety. Organizations using the affected FDS Web server should prioritize addressing this vulnerability to prevent potential data breaches and ensure the integrity of their systems.
Original NVD Description
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.