CVE-2020-12495: ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege management
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens". The vulnerability is that user sessions are not closed correctly and a user with fewer rights is assigned the higher rights when he logs on.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12495?
CVE-2020-12495 is considered a high severity vulnerability due to improper privilege management.
How do I fix CVE-2020-12495?
To fix CVE-2020-12495, upgrade the firmware of the Endress+Hauser Ecograph T devices to version 2.0.0 or later.
What are the potential impacts of CVE-2020-12495?
The potential impacts of CVE-2020-12495 include unauthorized access and modification of sensitive settings based on improper role management.
Which devices are affected by CVE-2020-12495?
Devices affected by CVE-2020-12495 include Endress+Hauser RSG35, ORSG35, RSG45, and ORSG45 with firmware versions prior to 2.0.0.
Is CVE-2020-12495 actively exploited in the wild?
There is currently no public information indicating that CVE-2020-12495 is being actively exploited in the wild.