Description
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.
Published: 2020-10-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

For ICRL-M-8RJ45/4SFP-G-DIN and ICRL-M-16RJ45/4CP-G-DIN: Update to Firmware 1.3.1 and deactivate TFTP-Service. For all other devices: An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4806 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.
History

No history.

Subscriptions

Korenix Jetwave 2212g Jetwave 2212g Firmware Jetwave 2212s Jetwave 2212s Firmware Jetwave 2212x Jetwave 2212x Firmware Jetwave 2311 Jetwave 2311 Firmware Jetwave 3220 Jetwave 3220 Firmware Jetwave 3420 Jetwave 3420 Firmware Jetwave 4510 Jetwave 4510 Firmware Jetwave 4706 Jetwave 4706 Firmware Jetwave 4706f Jetwave 4706f Firmware Jetwave 5010 Jetwave 5010 Firmware Jetwave 5310 Jetwave 5310 Firmware Jetwave 5428g-20sfp Jetwave 5428g-20sfp Firmware Jetwave 5810g Jetwave 5810g Firmware
Pepperl-fuchs Es7506 Es7506 Firmware Es7510 Es7510-xt Es7510-xt Firmware Es7510 Firmware Es7528 Es7528 Firmware Es8508 Es8508 Firmware Es8508f Es8508f Firmware Es8509-xt Es8509-xt Firmware Es8510 Es8510-xt Es8510-xt Firmware Es8510-xte Es8510-xte Firmware Es8510 Firmware Es9528 Es9528-xt Es9528-xt Firmware Es9528-xtv2 Es9528-xtv2 Firmware Es9528 Firmware Icrl-m-16rj45\/4cp-g-din Icrl-m-16rj45\/4cp-g-din Firmware Icrl-m-8rj45\/4sfp-g-din Icrl-m-8rj45\/4sfp-g-din Firmware
Westermo Pmi-110-f2g Pmi-110-f2g Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T17:09:09.147Z

Reserved: 2020-04-30T00:00:00.000Z

Link: CVE-2020-12504

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-15T19:15:11.993

Modified: 2024-11-21T04:59:49.320

Link: CVE-2020-12504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses