Impact
A low‑privileged remote attacker can exploit a local file inclusion flaw in the /index.php/ajax/save_iodd_parameters endpoint. By supplying a valid operator cookie, the attacker may cause the device to include arbitrary files, enabling execution of arbitrary PHP code. The vulnerability satisfies CWE‑98, which relates to improper validation of file existence or paths, leading to remote code execution.
Affected Systems
The flaw affects firmware on a range of industrial devices from Carlo Gavazzi Automation (models YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (models ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D) and Phoenix Contact (IOL MA8 EIP DI8 and IOL MA8 PN DI8).
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, and the EPSS score of 0.00861 (less than 1%) suggests a low but nonzero probability of exploitation in the CISA KEV catalog. Attackers can leverage a valid operator cookie to reach the /index.php/ajax/save_iodd_parameters endpoint, where they can include arbitrary files and execute PHP code with the privileges of the web service. Because this is a local file inclusion flaw (CWE‑98), it enables remote attackers to compromise device integrity and availability, posing a significant risk to industrial control systems.
OpenCVE Enrichment