Impact
The vulnerability is a system command injection flaw (CWE-78) that allows an unauthenticated attacker to upload a malicious IODD file. When accepted, the device writes a shell script to its filesystem and executes it with root privileges. The injected script remains active across reboots, providing persistent high‑privilege access to the compromised controller. The result is full compromise of the device, with potential to modify or delete data, inject code, or use the device as part of a botnet.
Affected Systems
Affected vendors are Carlo Gavazzi Automation, Pepperl+Fuchs, and Phoenix Contact. The specific product models included are YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO from Carlo Gavazzi; several ICE2 and ICE3 variants from Pepperl+Fuchs such as ICE2‑8IOL‑G65L‑V1D and ICE3‑8IOL‑G65L‑V1D‑Y; and IOL MA8 EIP DI8 and IOL MA8 PN DI8 from Phoenix Contact. No specific firmware or product versions have been supplied in the advisory.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is critical, but its EPSS score of <1% indicates it is rarely exploited in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is the open, unauthenticated IODD upload interface; once a malicious file is accepted, the device automatically writes and runs a root‑privileged script, which persists after reboot. The ease of exploitation means that any exposed controller with this interface is a high‑risk target.
OpenCVE Enrichment