Description
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.
Published: 2020-10-15
Score: 7.2 High
EPSS: 6.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4805 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.
History

No history.

Subscriptions

Korenix Jetnet 4510 Jetnet 4510 Firmware Jetnet 4706 Jetnet 4706 Firmware Jetnet 4706f Jetnet 4706f Firmware Jetnet 5010 Jetnet 5010 Firmware Jetnet 5310 Jetnet 5310 Firmware Jetnet 5428g-20sfp Jetnet 5428g-20sfp Firmware Jetnet 5810g Jetnet 5810g Firmware Jetnet 6095 Jetnet 6095 Firmware Jetwave 2212g Jetwave 2212g Firmware Jetwave 2212s Jetwave 2212s Firmware Jetwave 2212x Jetwave 2212x Firmware Jetwave 2311 Jetwave 2311 Firmware Jetwave 3220 Jetwave 3220 Firmware
Pepperl-fuchs Es7506 Es7506 Firmware Es7510 Es7510-xt Es7510-xt Firmware Es7510 Firmware Es7528 Es7528 Firmware Es8508 Es8508 Firmware Es8508f Es8508f Firmware Es8509-xt Es8509-xt Firmware Es8510 Es8510-xt Es8510-xt Firmware Es8510-xte Es8510-xte Firmware Es8510 Firmware Es9528 Es9528-xt Es9528-xt Firmware Es9528-xtv2 Es9528-xtv2 Firmware Es9528 Firmware Icrl-m-16rj45\/4cp-g-din Icrl-m-16rj45\/4cp-g-din Firmware Icrl-m-8rj45\/4sfp-g-din Icrl-m-8rj45\/4sfp-g-din Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-17T04:24:41.310Z

Reserved: 2020-04-30T00:00:00.000Z

Link: CVE-2020-12503

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-15T19:15:11.753

Modified: 2024-11-21T04:59:49.137

Link: CVE-2020-12503

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses