Impact
A command injection flaw in the Field_Shadow_Password class allows a low‑privileged remote attacker to execute arbitrary commands with root privileges on the device. The vulnerability is enabled through operator‑level credentials, enabling the attacker to bypass normal authorization checks. This weakness is classified as CWE‑78, which signifies unsafe command construction and execution.
Affected Systems
This flaw affects a range of industrial control devices. It is present in Carlo Gavazzi Automation firmware for the YL212 and YN115 series, in Pepperl+Fuchs ICE‑2 and ICE‑3 series firmware, and in Phoenix Contact IOL MA8 EIP and PN firmware. All models listed in the vendor product tables are potentially vulnerable, including the YL212CEI8M1IO, YN115CPN8RPIO, ICE2‑8IOL‑G65L‑V1D, ICE3‑8IOL‑K45P‑RJ45, and IOL MA8 DI8 variants.
Risk and Exploitability
The CVSS score of 8.8 marks this issue as high severity, indicating that exploitation could lead to severe system compromise. The EPSS score of 2% suggests that while exploitation is plausible, it is not ubiquitous, but the potential impact is significant. The vulnerability is not listed in CISA KEV, yet the remote command injection route—together with the need only for operator credentials—means that attackers with access to the network or device can leverage this flaw to gain full administrative control.
OpenCVE Enrichment