Description
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.
Published: 2020-10-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4802 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.
History

No history.

Subscriptions

Pepperl-fuchs Es7506 Es7506 Firmware Es7510 Es7510-xt Es7510-xt Firmware Es7510 Firmware Es7528 Es7528 Firmware Es8508 Es8508 Firmware Es8508f Es8508f Firmware Es8509-xt Es8509-xt Firmware Es8510 Es8510-xt Es8510-xt Firmware Es8510-xte Es8510-xte Firmware Es8510 Firmware Es9528 Es9528-xt Es9528-xt Firmware Es9528-xtv2 Es9528-xtv2 Firmware Es9528 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-17T01:10:49.072Z

Reserved: 2020-04-30T00:00:00.000Z

Link: CVE-2020-12500

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-15T19:15:11.440

Modified: 2024-11-21T04:59:48.630

Link: CVE-2020-12500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses