← Back

Pepperl Fuchs

pepperl-fuchs

27 CVEs • 230 products

Products (230)

Click to collapse
Toggle
Wcs Firmware
wcs_firmware
Btc12 Firmware
btc12_firmware
Btc14 Firmware
btc14_firmware
Pactware
pactware
Pha Firmware
pha_firmware
Btc12
btc12
Btc14
btc14
Es7510 Xt
es7510-xt
Es8509 Xt
es8509-xt
Es8510 Xt
es8510-xt
Es9528 Xtv2
es9528-xtv2
Es7506
es7506
Es7510
es7510
Es7528
es7528
Es8508
es8508
Es8508f
es8508f
Es8510
es8510
Es8510 Xte
es8510-xte
Es9528
es9528
Es9528 Xt
es9528-xt

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pepperl Fuchs
8Eip/modbus Firmware
Ethernet/ip FirmwareIcdm Rx/tcp Socketserver Firmware+5 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
1Pepperl Fuchs
8Eip/modbus Firmware
Ethernet/ip FirmwareIcdm Rx/tcp Socketserver Firmware+5 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
1Pepperl Fuchs
8Eip/modbus Firmware
Ethernet/ip FirmwareIcdm Rx/tcp Socketserver Firmware+5 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
1Pepperl Fuchs
4Oit1500 F113 B12 Cb Firmware
Oit200 F113 B12 Cb FirmwareOit500 F113 B12 Cb Firmware+1 more
Jun 17, 2026
Jul 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
1Pepperl Fuchs
4Oit1500 F113 B12 Cb Firmware
Oit200 F113 B12 Cb FirmwareOit500 F113 B12 Cb Firmware+1 more
Jun 17, 2026
Jul 10, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall base...Show more
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.Show less
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the u...Show more
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.Show less
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.
1Pepperl Fuchs
2Wha Gw F2d2 0 As Z2 Eth.eip Firmware
Wha Gw F2d2 0 As Z2 Eth Firmware
Jun 17, 2026
Aug 31, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.
2Hilscher
Pepperl Fuchs
9Ice1 16di G60l V1d Firmware
Ice1 16dio G60l C1 V1d FirmwareIce1 16dio G60l V1d Firmware+6 more
Jun 17, 2026
May 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.
2Hilscher
Pepperl Fuchs
8Ethernet/ip Adapter Firmware
Pcv100 F200 B25 V1d 6011 6720 FirmwarePcv100 F200 B25 V1d 6011 Firmware+5 more
Jun 17, 2026
Feb 16, 2021
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.
2Hilscher
Pepperl Fuchs
24Ohv F230 B17 Firmware
Oit500 F113b17 Cb FirmwarePcv100 F200 B17 V1d 6011 6997 Firmware+21 more
Jun 17, 2026
Feb 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.
4Emerson
Pepperl FuchsWago+1 more
7Dtminspector 3
Fdtcontainer ApplicationFdtcontainer Component+4 more
Jun 17, 2026
Jan 22, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
1Pepperl Fuchs
12Io Link Master 4 Eip Firmware
Io Link Master 4 Pnio FirmwareIo Link Master 8 Eip L Firmware+9 more
Jun 17, 2026
Jan 22, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd
1Pepperl Fuchs
12Io Link Master 4 Eip Firmware
Io Link Master 4 Pnio FirmwareIo Link Master 8 Eip L Firmware+9 more
Jun 17, 2026
Jan 22, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
1Pepperl Fuchs
12Io Link Master 4 Eip Firmware
Io Link Master 4 Pnio FirmwareIo Link Master 8 Eip L Firmware+9 more
Jun 17, 2026
Jan 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting