CVE-2020-12502: Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2020-12502.
What is the severity level of CVE-2020-12502?
The severity level of CVE-2020-12502 is high (8.8).
Which software versions are affected by CVE-2020-12502?
Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below are affected.
What is the description of CVE-2020-12502 vulnerability?
CVE-2020-12502 is an Improper Authorization vulnerability in Pepperl+Fuchs P+F Comtrol RocketLinx ES series firmware and ICRL-M devices FW 1.2.3 and below, which could allow unauthorized access.
Are there any references available for more details on CVE-2020-12502?
Yes, you can find more details on CVE-2020-12502 vulnerability at the following references: [Reference 1](http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html), [Reference 2](http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html), [Reference 3](http://seclists.org/fulldisclosure/2021/Jun/0).