CVE-2020-12501: Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-12501.
What is the severity of CVE-2020-12501?
The severity of CVE-2020-12501 is critical with a CVSS score of 9.8.
Which products are affected by CVE-2020-12501?
The Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, and ES9528/ES9528-XT (all versions) are affected by CVE-2020-12501.
What is the vulnerability in Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, and ES9528/ES9528-XT?
The vulnerability in Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, and ES9528/ES9528-XT is an improper authorization issue that allows the use of undocumented accounts.
How can I fix the issue related to CVE-2020-12501?
To fix the issue related to CVE-2020-12501, it is recommended to apply the latest firmware update provided by Pepperl+Fuchs for the affected products.