Impact
This vulnerability allows a low‑privileged attacker to send malformed IODD files to the /index.php/attached_devices_tab/do_upload endpoint, bypassing authorization checks. By uploading a crafted file, the attacker can potentially alter firmware settings or cause the device to crash. The weakness is an improper authorization issue (CWE‑863). The impact is limited to devices that accept IODD uploads, which may lead to unintended device behavior or denial of service.
Affected Systems
Devices affected are specific models from Carlo Gavazzi Automation (YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (ice2 and ice3 series such as ICE2‑8IOL‑G65L‑V1D, ICE3‑8IOL‑K45S‑RJ45, etc.), and Phoenix Contact (iOL MA8 EIP DI8 and iOL MA8 PN DI8). Firmware versions are indicated by the associated CPE strings, but no explicit version ranges are provided.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, yet the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in CISA KEV, so no publicly known exploit yet. The likely attack vector is remote over the network; the attacker must reach the web interface and have low‑privileged access. The absence of a publicly disclosed exploit suggests that active attack is unlikely, but the window of risk remains if device firmware is not updated.
OpenCVE Enrichment