CVE-2020-12495: ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege management

Published Nov 19, 2020
·
Updated

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens". The vulnerability is that user sessions are not closed correctly and a user with fewer rights is assigned the higher rights when he logs on.

Affected Software

8 affected components
Endress Rsg35 Firmware<2.0.0
Endress RSG35
Endress Rsg45 Firmware<2.0.0
Endress RSG45
Endress Orsg35 Firmware<2.0.0
Endress ORSG35
Endress Orsg45 Firmware<2.0.0
Endress ORSG45

Remediation

Information

Endress+Hauser will not change this behavior. Customers are recommended to take the measures for Temporary Fix / Mitigation as described above.

Event History

Nov 19, 2020
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2020-12495?

CVE-2020-12495 is considered a high severity vulnerability due to improper privilege management.

2

How do I fix CVE-2020-12495?

To fix CVE-2020-12495, upgrade the firmware of the Endress+Hauser Ecograph T devices to version 2.0.0 or later.

3

What are the potential impacts of CVE-2020-12495?

The potential impacts of CVE-2020-12495 include unauthorized access and modification of sensitive settings based on improper role management.

4

Which devices are affected by CVE-2020-12495?

Devices affected by CVE-2020-12495 include Endress+Hauser RSG35, ORSG35, RSG45, and ORSG45 with firmware versions prior to 2.0.0.

5

Is CVE-2020-12495 actively exploited in the wild?

There is currently no public information indicating that CVE-2020-12495 is being actively exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203