Description
A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.
Published: 2026-09-16
Score: 8.8 High
EPSS: 2.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection flaw in the Field_Shadow_Password class allows a low‑privileged remote attacker to execute arbitrary commands with root privileges on the device. The vulnerability is enabled through operator‑level credentials, enabling the attacker to bypass normal authorization checks. This weakness is classified as CWE‑78, which signifies unsafe command construction and execution.

Affected Systems

This flaw affects a range of industrial control devices. It is present in Carlo Gavazzi Automation firmware for the YL212 and YN115 series, in Pepperl+Fuchs ICE‑2 and ICE‑3 series firmware, and in Phoenix Contact IOL MA8 EIP and PN firmware. All models listed in the vendor product tables are potentially vulnerable, including the YL212CEI8M1IO, YN115CPN8RPIO, ICE2‑8IOL‑G65L‑V1D, ICE3‑8IOL‑K45P‑RJ45, and IOL MA8 DI8 variants.

Risk and Exploitability

The CVSS score of 8.8 marks this issue as high severity, indicating that exploitation could lead to severe system compromise. The EPSS score of 2% suggests that while exploitation is plausible, it is not ubiquitous, but the potential impact is significant. The vulnerability is not listed in CISA KEV, yet the remote command injection route—together with the need only for operator credentials—means that attackers with access to the network or device can leverage this flaw to gain full administrative control.

Generated by OpenCVE AI on September 16, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that removes the vulnerable command construction in the Field_Shadow_Password class.
  • If a firmware update is unavailable, disable the Field_Shadow_Password feature or restrict operator access to the affected interface.
  • Configure network segmentation or firewall rules to limit exposure of the impacted devices to untrusted networks.
  • Consider implementing a change‑management process that tracks operator credential usage and enforces strict least‑privilege practices.

Generated by OpenCVE AI on September 16, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.
Title Command Injection in Field_Shadow_Password Class
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T19:06:21.541Z

Reserved: 2026-02-20T13:10:29.715Z

Link: CVE-2026-27550

cve-icon Vulnrichment

Updated: 2026-09-16T19:06:14.712Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:37.487

Modified: 2026-09-16T19:17:11.227

Link: CVE-2026-27550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:15:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')