Impact
A remote attacker with low privileges can manipulate the schema path parameter in the web application's diagnostics endpoint, causing the system to expose all stored user password hashes. The flaw maps directly to CWE‑497, which describes information exposure through insecure storage or processing of sensitive data. Since the disclosure returns credentials, it threatens confidentiality and creates a credential compromise vector.
Affected Systems
Affected devices include several models from Carlo Gavazzi Automation (YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs products (ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D) and Phoenix Contact IOL MA8 devices (EIP‑DI8 and PN‑DI8). All of these models run firmware that exposes the vulnerable endpoint.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS of less than 1% suggests very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid authenticated session (user cookie) and remote access to the web interface, implying the attack vector is a remote network-controlled web request. Once exploited, the attacker can retrieve all password hashes, facilitating credential theft and potential lateral movement.
OpenCVE Enrichment