CVE-2020-12502
15.10.2020, 19:15
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.
Vendor | Product | Version |
---|---|---|
pepperl-fuchs | es7510-xt_firmware | * |
pepperl-fuchs | es8509-xt_firmware | * |
pepperl-fuchs | es8510-xt_firmware | * |
pepperl-fuchs | es9528-xtv2_firmware | * |
pepperl-fuchs | es7506_firmware | * |
pepperl-fuchs | es7510_firmware | * |
pepperl-fuchs | es7528_firmware | * |
pepperl-fuchs | es8508_firmware | * |
pepperl-fuchs | es8508f_firmware | * |
pepperl-fuchs | es8510_firmware | * |
pepperl-fuchs | es8510-xte_firmware | * |
pepperl-fuchs | es9528_firmware | * |
pepperl-fuchs | es9528-xt_firmware | * |
pepperl-fuchs | icrl-m-8rj45\/4sfp-g-din_firmware | 𝑥 ≤ 1.2.3 |
pepperl-fuchs | icrl-m-16rj45\/4cp-g-din_firmware | 𝑥 ≤ 1.2.3 |
korenix | jetnet_5428g-20sfp_firmware | - |
korenix | jetnet_5810g_firmware | - |
korenix | jetnet_4706f_firmware | - |
korenix | jetnet_4706_firmware | - |
korenix | jetnet_4510_firmware | - |
korenix | jetnet_5010_firmware | - |
korenix | jetnet_5310_firmware | - |
korenix | jetnet_6095_firmware | - |
pepperl-fuchs | icrl-m-8rj45\/4sfp-g-din_firmware | 𝑥 < 1.4 |
pepperl-fuchs | icrl-m-16rj45\/4cp-g-din_firmware | 𝑥 < 1.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References