CVE-2020-12503: Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12503?
CVE-2020-12503 has a medium severity level due to the improper authorization vulnerability it presents.
How do I fix CVE-2020-12503?
To fix CVE-2020-12503, update the firmware of the affected Pepperl+Fuchs devices to the latest available version.
What devices are affected by CVE-2020-12503?
CVE-2020-12503 affects various models such as the Pepperl+Fuchs RocketLinx ES7510-XT, ES8509-XT, and several ICRL-M devices.
What kind of vulnerability is CVE-2020-12503?
CVE-2020-12503 is categorized as an improper authorization vulnerability that could allow unauthorized access to device functions.
Is CVE-2020-12503 being actively exploited?
As of now, there have been no confirmed reports of active exploitation of CVE-2020-12503 in the wild.