Impact
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured. This flaw allows an attacker to gain privileged access, compromising the confidentiality and integrity of the device’s configuration and potentially enabling further attacks.
Affected Systems
The vulnerability affects firmware of devices produced by Carlo Gavazzi Automation, Pepperl+Fuchs, and Phoenix Contact. Specific products include the YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE2-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D (and variants), ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, IOL MA8 EIP DI8, and IOL MA8 PN DI8. No specific firmware version information is supplied.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS score of less than 1% suggests a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. The attack likely originates from a remote network attacker who sends crafted requests to the device’s authentication endpoint. The bypass enables the attacker to create an admin session without credentials, making it a high-impact privilege escalation issue.
OpenCVE Enrichment