FKIE_CVE-2020-12502

Vulnerability from fkie_nvd - Published: 2020-10-15 19:15 - Updated: 2026-06-17 02:51
Summary
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.
References
info@cert.vde.comhttp://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.htmlExploit, Third Party Advisory, VDB Entry
info@cert.vde.comhttp://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.htmlExploit, Third Party Advisory, VDB Entry
info@cert.vde.comhttp://seclists.org/fulldisclosure/2021/Jun/0Mailing List, Third Party Advisory
info@cert.vde.comhttps://cert.vde.com/de-de/advisories/vde-2020-040Third Party Advisory
info@cert.vde.comhttps://cert.vde.com/en-us/advisories/vde-2020-053Third Party Advisory
info@cert.vde.comhttps://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/Exploit, Third Party Advisory
af854a3a-2127-422b-91ae-364da2661108http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.htmlExploit, Third Party Advisory, VDB Entry
af854a3a-2127-422b-91ae-364da2661108http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.htmlExploit, Third Party Advisory, VDB Entry
af854a3a-2127-422b-91ae-364da2661108http://seclists.org/fulldisclosure/2021/Jun/0Mailing List, Third Party Advisory
af854a3a-2127-422b-91ae-364da2661108https://cert.vde.com/de-de/advisories/vde-2020-040Third Party Advisory
af854a3a-2127-422b-91ae-364da2661108https://cert.vde.com/en-us/advisories/vde-2020-053Third Party Advisory
af854a3a-2127-422b-91ae-364da2661108https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/Exploit, Third Party Advisory
Impacted products
Vendor Product Version
pepperl-fuchs es7510-xt_firmware *
pepperl-fuchs es7510-xt -
pepperl-fuchs es8509-xt_firmware *
pepperl-fuchs es8509-xt -
pepperl-fuchs es8510-xt_firmware *
pepperl-fuchs es8510-xt -
pepperl-fuchs es9528-xtv2_firmware *
pepperl-fuchs es9528-xtv2 -
pepperl-fuchs es7506_firmware *
pepperl-fuchs es7506 -
pepperl-fuchs es7510_firmware *
pepperl-fuchs es7510 -
pepperl-fuchs es7528_firmware *
pepperl-fuchs es7528 -
pepperl-fuchs es8508_firmware *
pepperl-fuchs es8508 -
pepperl-fuchs es8508f_firmware *
pepperl-fuchs es8508f -
pepperl-fuchs es8510_firmware *
pepperl-fuchs es8510 -
pepperl-fuchs es8510-xte_firmware *
pepperl-fuchs es8510-xte -
pepperl-fuchs es9528_firmware *
pepperl-fuchs es9528 -
pepperl-fuchs es9528-xt_firmware *
pepperl-fuchs es9528-xt -
pepperl-fuchs icrl-m-8rj45\/4sfp-g-din_firmware *
pepperl-fuchs icrl-m-8rj45\/4sfp-g-din -
pepperl-fuchs icrl-m-16rj45\/4cp-g-din_firmware *
pepperl-fuchs icrl-m-16rj45\/4cp-g-din -
korenix jetnet_5428g-20sfp_firmware -
korenix jetnet_5428g-20sfp -
korenix jetnet_5810g_firmware -
korenix jetnet_5810g -
korenix jetnet_4706f_firmware -
korenix jetnet_4706f -
korenix jetnet_4706_firmware -
korenix jetnet_4706 -
korenix jetnet_4510_firmware -
korenix jetnet_4510 -
korenix jetnet_5010_firmware -
korenix jetnet_5010 -
korenix jetnet_5310_firmware -
korenix jetnet_5310 -
korenix jetnet_6095_firmware -
korenix jetnet_6095 -
pepperl-fuchs icrl-m-8rj45\/4sfp-g-din_firmware *
pepperl-fuchs icrl-m-8rj45\/4sfp-g-din -
pepperl-fuchs icrl-m-16rj45\/4cp-g-din_firmware *
pepperl-fuchs icrl-m-16rj45\/4cp-g-din -

{
  "affected": [
    {
      "affectedData": [
        {
          "product": "P+F Comtrol RocketLinx",
          "vendor": "Pepperl+Fuchs",
          "versions": [
            {
              "status": "affected",
              "version": "ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F,  ES8510-XTE, ES9528/ES9528-XT all"
            },
            {
              "lessThan": "2.1.1",
              "status": "affected",
              "version": "ES7510-XT",
              "versionType": "custom"
            },
            {
              "lessThan": "3.1.1",
              "status": "affected",
              "version": "ES8510",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "P+F Comtrol RocketLinx",
          "vendor": "Pepperl+Fuchs",
          "versions": [
            {
              "lessThanOrEqual": "1.2.3",
              "status": "affected",
              "version": "ICRL-M-8RJ45/4SFP-G-DIN",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "1.2.3",
              "status": "affected",
              "version": "ICRL-M-16RJ45/4CP-G-DIN",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "JetNet",
          "vendor": "Korenix",
          "versions": [
            {
              "lessThanOrEqual": "V1.0",
              "status": "affected",
              "version": "5428G-20SFP",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "V1.1",
              "status": "affected",
              "version": "5810G",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "V2.3b",
              "status": "affected",
              "version": "4706F",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "V3.0b",
              "status": "affected",
              "version": "4510",
              "versionType": "custom"
            },
            {
              "lessThan": "V1.6",
              "status": "affected",
              "version": "5310",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "PMI-110-F2G",
          "vendor": "Westermo",
          "versions": [
            {
              "lessThan": "V1.8",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ],
      "source": "info@cert.vde.com"
    }
  ],
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es7510-xt_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "69279E51-1B3D-40F1-BC05-E7DE4FCF81D0",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es7510-xt:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E3FA814F-1C0E-4400-AA54-62520BD62F49",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es8509-xt_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "235B73CF-E9EE-46BC-A89F-A27EC816420F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es8509-xt:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "663998ED-61CC-40CE-A580-4D40E28FA5DB",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es8510-xt_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "EEE2FFF7-9BEC-4456-9659-F1BC3E72508C",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es8510-xt:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "CF4AB5DA-CFEB-4F15-948D-1B5E08ADB370",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es9528-xtv2_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "8DFE9808-FA4D-4D8D-836D-7896ABD4DB6F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es9528-xtv2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B1B6AD07-2B10-4B56-A08E-D9DBF98FF06E",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es7506_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "0BAB2AE4-E231-4485-89D3-4B153E7DFA60",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es7506:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "7CA6817C-7F79-42D9-BD4A-87B9278EE005",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es7510_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "9A81A766-C11C-4F1F-8D6D-66DA1067D04A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es7510:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F5AC80E6-5276-4209-8C11-889A88547934",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es7528_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "08F78AC1-DD60-4035-A573-1FBC94BC2CFB",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es7528:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0EF18AA-0305-48E6-BA3E-0921AAFAD21A",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es8508_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F83E1070-A455-46A2-B677-1C55B78A872A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es8508:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "35D1152B-2CC1-47CB-967C-450E54AA0AC2",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es8508f_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "679D27C7-C1AD-4B5F-9EF6-8559EDC48190",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es8508f:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E2AB75DB-57CA-49C5-86AB-75D766F23D24",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es8510_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "44ECCFCA-EE3D-4E66-BFB9-D5DC2CBBCB69",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es8510:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8C58A4C3-2DD2-4B24-8C16-806041276486",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es8510-xte_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "EB4475C9-C8B6-4BE7-9DEC-4E3BD3616711",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es8510-xte:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "89EB4DB0-519A-47DD-B1A5-AD50071DD045",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es9528_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F8B014C8-A75E-4A84-BB99-183CC44EB090",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es9528:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "5942FAF3-99D9-421A-92E3-5CA16A5B3E5F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:es9528-xt_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "EF77744F-88F7-44E9-AA5C-7D0F0B664FAC",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:es9528-xt:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F3F2C76E-3724-4626-B25E-EBCF5FE74C90",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:icrl-m-8rj45\\/4sfp-g-din_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "1B5520C5-3AA7-42CD-87E5-7B19DEF1D724",
              "versionEndIncluding": "1.2.3",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:icrl-m-8rj45\\/4sfp-g-din:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "49D839E1-3306-4211-A168-C5C2A8B5A40C",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:icrl-m-16rj45\\/4cp-g-din_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "FB335DAA-18BB-4358-B9EF-3EC46214A292",
              "versionEndIncluding": "1.2.3",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:icrl-m-16rj45\\/4cp-g-din:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "376BBE27-BC5B-4A8A-9DF6-C9982A797953",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:korenix:jetnet_5428g-20sfp_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "327FC8D6-E59D-4DC5-918B-0AEBB07B2075",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:korenix:jetnet_5428g-20sfp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "41A504D7-8B61-4D78-9D66-9687D6110F47",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:korenix:jetnet_5810g_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "AD9A573B-3C73-4212-A562-C912EDF0C881",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:korenix:jetnet_5810g:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6C6C2282-D4E5-40FC-9C1A-749C1B1C623A",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:korenix:jetnet_4706f_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "83D1F86D-261B-490C-A4A3-EAAA5DB2B8E7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:korenix:jetnet_4706f:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "875F22D5-57B9-43EB-A92C-9FB0EA948164",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:korenix:jetnet_4706_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "AF01FC6A-9196-4B41-ACB1-46FC2EAD9A92",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:korenix:jetnet_4706:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DD089EE1-3D71-430C-9CA9-BE32470BEE27",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:korenix:jetnet_4510_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "4AF6BE33-3CC3-4488-AF8E-6A5096F15C9D",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:korenix:jetnet_4510:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C864A6A1-5E58-4EFE-85FC-DEDFBBC36473",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:korenix:jetnet_5010_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "4F6BC0FF-63A0-4ADD-BD3A-F6DD1DB61356",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:korenix:jetnet_5010:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0896AC09-3022-4A14-93DB-D6BE6795C615",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:korenix:jetnet_5310_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "37A42256-647A-4637-B05F-A9D70838A281",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:korenix:jetnet_5310:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "86BE9095-B0A6-4268-AC78-453C462FB80B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:korenix:jetnet_6095_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "3BDA9563-F33F-4CC8-96F8-4B9954738A05",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:korenix:jetnet_6095:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E5E6FE6C-873E-4C58-B590-3888BCE38F1D",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:icrl-m-8rj45\\/4sfp-g-din_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "5389E374-F055-4EC7-B31B-9DBD3D1B2A30",
              "versionEndExcluding": "1.4",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:icrl-m-8rj45\\/4sfp-g-din:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "49D839E1-3306-4211-A168-C5C2A8B5A40C",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pepperl-fuchs:icrl-m-16rj45\\/4cp-g-din_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "FDCC2EF5-2277-44F6-BEAC-71F8C39BE6EF",
              "versionEndExcluding": "1.4.0",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pepperl-fuchs:icrl-m-16rj45\\/4cp-g-din:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "376BBE27-BC5B-4A8A-9DF6-C9982A797953",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de Autorizaci\u00f3n Inapropiada de Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528-XT (todas las versiones) e ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW versiones 1.2.3 y por debajo, son propensos a una administraci\u00f3n de dispositivos no autenticados"
    }
  ],
  "id": "CVE-2020-12502",
  "lastModified": "2026-06-17T02:51:55.367",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "MEDIUM",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "PARTIAL",
          "baseScore": 6.8,
          "confidentialityImpact": "PARTIAL",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "version": "2.0"
        },
        "exploitabilityScore": 8.6,
        "impactScore": 6.4,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 8.8,
          "baseSeverity": "HIGH",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "REQUIRED",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 2.8,
        "impactScore": 5.9,
        "source": "info@cert.vde.com",
        "type": "Secondary"
      },
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 8.8,
          "baseSeverity": "HIGH",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "REQUIRED",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 2.8,
        "impactScore": 5.9,
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  },
  "published": "2020-10-15T19:15:11.643",
  "references": [
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "url": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html"
    },
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "url": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html"
    },
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "url": "http://seclists.org/fulldisclosure/2021/Jun/0"
    },
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "https://cert.vde.com/de-de/advisories/vde-2020-040"
    },
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "https://cert.vde.com/en-us/advisories/vde-2020-053"
    },
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "url": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "url": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "url": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "url": "http://seclists.org/fulldisclosure/2021/Jun/0"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "https://cert.vde.com/de-de/advisories/vde-2020-040"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "https://cert.vde.com/en-us/advisories/vde-2020-053"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "url": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com",
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ],
      "source": "info@cert.vde.com",
      "type": "Secondary"
    },
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Secondary"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Detection rules are retrieved from Rulezet.

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…