Vulnerability Description
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pepperl-Fuchs | Io-Link Master 4-Eip Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master 4-Eip | - |
| Pepperl-Fuchs | Io-Link Master 8-Eip Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master 8-Eip | - |
| Pepperl-Fuchs | Io-Link Master 8-Eip-L Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master 8-Eip-L | - |
| Pepperl-Fuchs | Io-Link Master Dr-8-Eip Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master Dr-8-Eip | - |
| Pepperl-Fuchs | Io-Link Master Dr-8-Eip-P Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master Dr-8-Eip-P | - |
| Pepperl-Fuchs | Io-Link Master Dr-8-Eip-T Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master Dr-8-Eip-T | - |
| Pepperl-Fuchs | Io-Link Master 4-Pnio Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master 4-Pnio | - |
| Pepperl-Fuchs | Io-Link Master 8-Pnio Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master 8-Pnio | - |
| Pepperl-Fuchs | Io-Link Master 8-Pnio-L Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master 8-Pnio-L | - |
| Pepperl-Fuchs | Io-Link Master Dr-8-Pnio Firmware | <= 1.5.48 |
| Pepperl-Fuchs | Io-Link Master Dr-8-Pnio | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en-us/advisories/vde-2020-038Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2020-038Third Party Advisory
FAQ
What is CVE-2020-12511?
CVE-2020-12511 is a vulnerability with a CVSS score of 8.8 (HIGH). Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.
How severe is CVE-2020-12511?
CVE-2020-12511 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12511?
Check the references section above for vendor advisories and patch information. Affected products include: Pepperl-Fuchs Io-Link Master 4-Eip Firmware, Pepperl-Fuchs Io-Link Master 4-Eip, Pepperl-Fuchs Io-Link Master 8-Eip Firmware, Pepperl-Fuchs Io-Link Master 8-Eip, Pepperl-Fuchs Io-Link Master 8-Eip-L Firmware.