First published: Mon Jan 04 2021(Updated: )
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pepperl-fuchs Io-link Master 4-eip Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master 4-eip | ||
Pepperl-fuchs Io-link Master 8-eip Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master 8-eip | ||
Pepperl-fuchs Io-link Master 8-eip-l Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master 8-eip-l | ||
Pepperl-fuchs Io-link Master Dr-8-eip Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master Dr-8-eip | ||
Pepperl-fuchs Io-link Master Dr-8-eip-p Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master Dr-8-eip-p | ||
Pepperl-fuchs Io-link Master Dr-8-eip-t Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master Dr-8-eip-t | ||
Pepperl-fuchs Io-link Master 4-pnio Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master 4-pnio | ||
Pepperl-fuchs Io-link Master 8-pnio Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master 8-pnio | ||
Pepperl-fuchs Io-link Master 8-pnio-l Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master 8-pnio-l | ||
Pepperl-fuchs Io-link Master Dr-8-pnio Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master Dr-8-pnio | ||
Pepperl-fuchs Io-link Master Dr-8-pnio-p Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master Dr-8-pnio-p | ||
Pepperl-fuchs Io-link Master Dr-8-pnio-t Firmware | <=1.5.48 | |
Pepperl-fuchs Io-link Master Dr-8-pnio-t |
In order to prevent the exploitation of the reported vulnerabilities, we recommend that the affected units be updated with the following three firmware packages: U-Boot bootloader version 1.36 or newer System image version 1.52 or newer Application base version 1.6.11 or newer
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12514 refers to a vulnerability in Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below that can be exploited to cause a Denial of Service (DoS) in discoveryd.
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is affected by CVE-2020-12514.
CVE-2020-12514 has a severity rating of 4.9 out of 10, indicating a medium-level vulnerability.
To fix CVE-2020-12514, users should update Pepperl+Fuchs Comtrol IO-Link Master to a version above 1.5.48, as this vulnerability has been patched in later versions.
More information about CVE-2020-12514 can be found in the advisory VDE-2020-038 published by VDE-CERT. The advisory provides additional details and recommendations.