CVE-2020-12500: Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-12500?
CVE-2020-12500 refers to an Improper Authorization vulnerability in Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) that allows unauthenticated device administration.
How severe is CVE-2020-12500?
CVE-2020-12500 has a severity rating of 9.8 (Critical).
How does CVE-2020-12500 affect Pepperl+Fuchs devices?
CVE-2020-12500 affects Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) by allowing unauthenticated device administration.
Is Pepperl+Fuchs ES7510-XT vulnerable to CVE-2020-12500?
Pepperl+Fuchs ES7510-XT is vulnerable to CVE-2020-12500.
How can I fix CVE-2020-12500 on Pepperl+Fuchs devices?
To fix CVE-2020-12500 on Pepperl+Fuchs devices, it is recommended to apply the latest firmware update provided by Pepperl+Fuchs.