CVE-2020-12525: WAGO/M&M Software Deserialization of untrusted data in fdtCONTAINER component
Published Jan 22, 2021
·Updated
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Affected Software
32 affected components
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik fdtCONTAINER component
Versions between 3.5.0 and 3.5.20304.x
Versions between 3.6.0 and 3.6.20304.x
Versions older than 3.5
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik Versions between 3.5.0 and 3.5.20304.x
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik Versions between 3.6.0 and 3.6.20304.x
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik Versions older than 3.5
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik fdtCONTAINER application
Versions between 4.5.0 and 4.5.20304.x
Versions between 4.6.0 and 4.6.20304.x
Versions older than 4.5
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik Versions between 4.5.0 and 4.5.20304.x
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik Versions between 4.6.0 and 4.6.20304.x
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik Versions older than 4.5
M&M Software GmbH, a subsidiary of WAGO Kontakttechnik dtmINSPECTOR Version 3 (Based on FDT 1.2.x)
Emerson Rosemount Transmitter Interface Software
Pepperl-fuchs Pactware>=5.0<=5.0.5.31
WAGO Dtminspector 3
WAGO Fdtcontainer Application<4.5
WAGO Fdtcontainer Application>=4.5.0<=4.5.20304
WAGO Fdtcontainer Application>=4.6.0<=4.6.20304
WAGO fdtCONTAINER Component<3.5
WAGO fdtCONTAINER Component>=3.5.0<=3.5.20304
WAGO fdtCONTAINER Component>=3.6.0<=3.6.20304
Weidmueller Wi Manager<=2.5.1
Pepperl-fuchs Io-link Master Firmware<=1.5.48
Pepperl-fuchs Io-link Master 4-eip
Pepperl-fuchs Io-link Master 4-pnio
Pepperl-fuchs Io-link Master 8-eip
Pepperl-fuchs Io-link Master 8-eip-l
Pepperl-fuchs Io-link Master 8-pnio
Pepperl-fuchs Io-link Master 8-pnio-l
Pepperl-fuchs Io-link Master Dr-8-eip
Pepperl-fuchs Io-link Master Dr-8-eip-p
Pepperl-fuchs Io-link Master Dr-8-eip-t
Pepperl-fuchs Io-link Master Dr-8-pnio
Pepperl-fuchs Io-link Master Dr-8-pnio-p
Pepperl-fuchs Io-link Master Dr-8-pnio-t
Remediation
Information
M&M Software provides two updated fdtCONTAINER component trees (3.6.20304.x < 3.7 and >= 3.7) see advisory https://cert.vde.com/en-us/advisories/vde-2020-048 for details.
Event History
Jan 22, 2021
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-12525.
2
What is the severity of CVE-2020-12525?
The severity of CVE-2020-12525 is high with a CVSS score of 7.8.
3
Which software versions are affected by CVE-2020-12525?
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x are affected by CVE-2020-12525.
4
How can I fix CVE-2020-12525?
There is no known fix or patch available for CVE-2020-12525 at this time. It is recommended to follow the guidance provided by the vendors and monitor for any updates.
5
Where can I find more information about CVE-2020-12525?
You can find more information about CVE-2020-12525 on the official websites of VDE and US-CERT.