CVE-2020-12513

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
pepperl-fuchsio-link_master_4-eip_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_8-eip_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_8-eip-l_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_dr-8-eip_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_dr-8-eip-p_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_dr-8-eip-t_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_4-pnio_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_8-pnio_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_8-pnio-l_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_dr-8-pnio_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_dr-8-pnio-p_firmware
𝑥
≤ 1.5.48
pepperl-fuchsio-link_master_dr-8-pnio-t_firmware
𝑥
≤ 1.5.48
𝑥
= Vulnerable software versions