CVE-2024-38502: Pepperl+Fuchs: Device Master ICDM-RX/* XSS vulnerability allows stored XSS
Published Aug 13, 2024
·Updated
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
Affected Software
48 affected components
All of the following
Pepperl-fuchs Icdm-rx\/tcp Socketserver Firmware<11.65
Any of the following
Pepperl-fuchs Icdm-rx\/tcp-16db9\/rj45-rm
Pepperl-fuchs Icdm-rx\/tcp-16rj45\/2rj45-pm
Pepperl-fuchs Icdm-rx\/tcp-16rj45\/rj45-rm
Pepperl-fuchs Icdm-rx\/tcp-2db9\/rj45-din
Pepperl-fuchs Icdm-rx\/tcp-2st\/rj45-din
Pepperl-fuchs Icdm-rx\/tcp-32rj45\/rj45-rm
Pepperl-fuchs Icdm-rx\/tcp-4db9\/2rj45-din
Pepperl-fuchs Icdm-rx\/tcp-4db9\/2rj45-pm
Pepperl-fuchs Icdm-rx\/tcp-8db9\/2rj45-pm
Pepperl-fuchs Icdm-rx\/tcp-db9\/rj45-din
Pepperl-fuchs Icdm-rx\/tcp-db9\/rj45-pm
Pepperl-fuchs Icdm-rx\/tcp-db9\/rj45-pm2
Pepperl-fuchs Icdm-rx\/tcp-st\/rj45-din
All of the following
Pepperl-fuchs Profinet Firmware<3.4.9
Any of the following
Pepperl-fuchs Icdm-rx\/pn-2db9\/rj45-din
Pepperl-fuchs Icdm-rx\/pn-2st\/rj45-din
Pepperl-fuchs Icdm-rx\/pn-4db9\/2rj45-din
Pepperl-fuchs Icdm-rx\/pn-db9\/rj45-din
Pepperl-fuchs Icdm-rx\/pn-db9\/rj45-pm
Pepperl-fuchs Icdm-rx\/pn-st\/rj45-din
All of the following
Pepperl-fuchs Profinet\/modbus Firmware<1.0.7
Any of the following
Pepperl-fuchs Icdm-rx\/pn1-2db9\/rj45-din
Pepperl-fuchs Icdm-rx\/pn1-2st\/rj45-din
Pepperl-fuchs Icdm-rx\/pn1-4db9\/2rj45-din
Pepperl-fuchs Icdm-rx\/pn1-db9\/rj45-din
Pepperl-fuchs Icdm-rx\/pn1-db9\/rj45-pm
Pepperl-fuchs Icdm-rx\/pn1-st\/rj45-din
All of the following
Any of the following
Pepperl-fuchs Modbus Router Firmware<7.09
Pepperl-fuchs Modbus Server Firmware<7.11
Pepperl-fuchs Modbus Tcp Firmware<7.11
Any of the following
Pepperl-fuchs Icdm-rx\/mod-4db9\/2rj45-din
Pepperl-fuchs Icdm-rx\/mod-db9\/rj45-din
Pepperl-fuchs Icdm-rx\/mod-st\/rj45-din
All of the following
Pepperl-fuchs Ethernet\/ip Firmware<7.22
Any of the following
Pepperl-fuchs Icdm-rx\/en-2db9\/rj45-din
Pepperl-fuchs Icdm-rx\/en-2st\/rj45-din
Pepperl-fuchs Icdm-rx\/en-4db9\/2rj45-din
Pepperl-fuchs Icdm-rx\/en-db9\/rj45-din
Pepperl-fuchs Icdm-rx\/en-db9\/rj45-pm
Pepperl-fuchs Icdm-rx\/en-st\/rj45-din
All of the following
Pepperl-fuchs Eip\/modbus Firmware<1.08
Any of the following
Pepperl-fuchs Icdm-rx\/en1-2db9\/rj45-din
Pepperl-fuchs Icdm-rx\/en1-2st\/rj45-din
Pepperl-fuchs Icdm-rx\/en1-4db9\/2rj45-din
Pepperl-fuchs Icdm-rx\/en1-db9\/rj45-din
Pepperl-fuchs Icdm-rx\/en1-db9\/rj45-pm
Pepperl-fuchs Icdm-rx\/en1-st\/rj45-din
Event History
Aug 13, 2024
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38502?
CVE-2024-38502 is considered a critical vulnerability due to its potential for an unauthenticated remote attack.
2
How can I fix CVE-2024-38502?
To mitigate CVE-2024-38502, update affected Pepperl-Fuchs firmware to versions above 11.65 for TCP Socketserver and above 3.4.9 for Profinet.
3
What does CVE-2024-38502 exploit?
CVE-2024-38502 exploits a stored XSS vulnerability, allowing attackers to obtain sensitive information or reboot devices.
4
Which devices are affected by CVE-2024-38502?
CVE-2024-38502 affects various Pepperl-Fuchs Icdm-rx and Profinet firmware versions prior to the specified secure versions.
5
Is user authentication sufficient to protect against CVE-2024-38502?
No, CVE-2024-38502 is a stored XSS vulnerability that can be exploited without user authentication.