Description
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.
Published: 2020-10-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4802 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.
History

No history.

Subscriptions

Pepperl-fuchs Es7506 Es7506 Firmware Es7510 Es7510-xt Es7510-xt Firmware Es7510 Firmware Es7528 Es7528 Firmware Es8508 Es8508 Firmware Es8508f Es8508f Firmware Es8509-xt Es8509-xt Firmware Es8510 Es8510-xt Es8510-xt Firmware Es8510-xte Es8510-xte Firmware Es8510 Firmware Es9528 Es9528-xt Es9528-xt Firmware Es9528-xtv2 Es9528-xtv2 Firmware Es9528 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-17T01:10:49.072Z

Reserved: 2020-04-30T00:00:00.000Z

Link: CVE-2020-12500

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-15T19:15:11.440

Modified: 2024-11-21T04:59:48.630

Link: CVE-2020-12500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses