CVE-2020-12504: Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12504?
CVE-2020-12504 has a medium severity rating due to improper authorization vulnerabilities that can lead to unauthorized access.
How do I fix CVE-2020-12504?
To mitigate CVE-2020-12504, update the affected Pepperl+Fuchs firmware to the latest version as recommended by the vendor.
Which products are affected by CVE-2020-12504?
CVE-2020-12504 affects several Pepperl+Fuchs models including the RocketLinx ES7510-XT, ES8509-XT, and others, as well as specific versions of ICRL-M devices.
What are the potential risks associated with CVE-2020-12504?
The risks include unauthorized access to network devices, which could lead to data manipulation or denial of service.
Is there a workaround for CVE-2020-12504 before applying a fix?
Currently, there are no reliable workarounds for CVE-2020-12504; users should prioritize updating the firmware.