CVE-2020-12503
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.
Affected (30)
Products: Pepperl Fuchs: Es7510 Xt Firmware, Es8509 Xt Firmware, Es8510 Xt Firmware, Es9528 Xtv2 Firmware, Es7506 Firmware, Es7510 Firmware, Es7528 Firmware, Es8508 Firmware, Es8508f Firmware, Es8510 Firmware, Es8510 Xte Firmware, Es9528 Firmware, Es9528 Xt Firmware, Icrl M 8rj45/4sfp G Din Firmware, Icrl M 16rj45/4cp G Din Firmware · Korenix: Jetnet 5428g 20sfp Firmware, Jetnet 5810g Firmware, Jetnet 4706f Firmware, Jetnet 4706 Firmware, Jetnet 4510 Firmware, Jetnet 5010 Firmware, Jetnet 5310 Firmware, Jetnet 6095 Firmware, Jetwave 2212x Firmware, Jetwave 2212s Firmware, Jetwave 2212g Firmware, Jetwave 2311 Firmware, Jetwave 3220 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es7510 Xt | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es8509 Xt | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es8510 Xt | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es9528 Xtv2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es7506 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es7510 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es7528 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es8508 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es8508f | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es8510 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es8510 Xte | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es9528 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Es9528 Xt | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.1 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.1 |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetnet 5428g 20sfp | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetnet 5810g | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetnet 4706f | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetnet 4706 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetnet 4510 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetnet 5010 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetnet 5310 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetnet 6095 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Icrl M 16rj45/4cp G Din | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pepperl Fuchs Icrl M 8rj45/4sfp G Din | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetwave 2212x | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetwave 2212s | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetwave 2212g | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetwave 2311 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Korenix Jetwave 3220 | All versions |
References (12)
Source: info@cert.vde.com
ExploitThird Party AdvisoryVDB Entry
Source: info@cert.vde.com
ExploitThird Party AdvisoryVDB Entry
Source: info@cert.vde.com
Mailing ListThird Party Advisory
Source: info@cert.vde.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.