Impact
An unauthenticated attacker can exploit a path traversal flaw in the /index.php/view_uploaded_iodd_file endpoint, enabling the download of the device’s SSH private key files. This vulnerability allows the attacker to read critical cryptographic material, potentially granting them full control over communication channels and enabling future persistence or man‑in‑the‑middle attacks. The weakness is a classic Path Traversal (CWE‑35) that bypasses normal file access restrictions.
Affected Systems
The flaw affects multiple industrial automation devices from Carlo Gavazzi Automation, Pepperl+Fuchs, and Phoenix Contact. Specific models include YL212CEI8M1IO and YL212CPN8M1IO, YN115CEI8RPIO and YN115CPN8RPIO, ICE2 and ICE3 firmware variants, and IOL MA8 EIP DI8 and IOL MA8 PN DI8 firmware. No version ranges are provided, but the vulnerability is tied to the embedded firmware that contains the vulnerable endpoint.
Risk and Exploitability
The CVSS score of 7.5 marks the issue as high severity, and the EPSS score indicates a low but non‑zero exploitation probability (<1 %). The vulnerability is not included in CISA’s KEV catalog, suggesting limited public exploitation yet. The attack can be carried out over a network by browsing to the vulnerable endpoint, after which the attacker can navigate to arbitrary files within the system’s file hierarchy. Since the exploit requires no authentication, any network access to the web interface can be used by an attacker to obtain confidential configuration data.
OpenCVE Enrichment