Vulnerability Description
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pepperl-Fuchs | Es7510-Xt Firmware | All versions |
| Pepperl-Fuchs | Es7510-Xt | - |
| Pepperl-Fuchs | Es8509-Xt Firmware | All versions |
| Pepperl-Fuchs | Es8509-Xt | - |
| Pepperl-Fuchs | Es8510-Xt Firmware | All versions |
| Pepperl-Fuchs | Es8510-Xt | - |
| Pepperl-Fuchs | Es9528-Xtv2 Firmware | All versions |
| Pepperl-Fuchs | Es9528-Xtv2 | - |
| Pepperl-Fuchs | Es7506 Firmware | All versions |
| Pepperl-Fuchs | Es7506 | - |
| Pepperl-Fuchs | Es7510 Firmware | All versions |
| Pepperl-Fuchs | Es7510 | - |
| Pepperl-Fuchs | Es7528 Firmware | All versions |
| Pepperl-Fuchs | Es7528 | - |
| Pepperl-Fuchs | Es8508 Firmware | All versions |
| Pepperl-Fuchs | Es8508 | - |
| Pepperl-Fuchs | Es8508F Firmware | All versions |
| Pepperl-Fuchs | Es8508F | - |
| Pepperl-Fuchs | Es8510 Firmware | All versions |
| Pepperl-Fuchs | Es8510 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-CommaExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-CommExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Jun/0ExploitMailing ListThird Party Advisory
- https://cert.vde.com/de-de/advisories/vde-2020-040Third Party Advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabiliThird Party Advisory
- http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-CommaExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-CommExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Jun/0ExploitMailing ListThird Party Advisory
- https://cert.vde.com/de-de/advisories/vde-2020-040Third Party Advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabiliThird Party Advisory
FAQ
What is CVE-2020-12500?
CVE-2020-12500 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT...
How severe is CVE-2020-12500?
CVE-2020-12500 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-12500?
Check the references section above for vendor advisories and patch information. Affected products include: Pepperl-Fuchs Es7510-Xt Firmware, Pepperl-Fuchs Es7510-Xt, Pepperl-Fuchs Es8509-Xt Firmware, Pepperl-Fuchs Es8509-Xt, Pepperl-Fuchs Es8510-Xt Firmware.