VYPR
Vendor

Pepperl Fuchs

Products
81
CVEs
22
Across products
130
Status
Private

Products

81
View all 81 products →

Recent CVEs

22
View all 22 CVEs →
  • CVE-2024-6422CriJul 10, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

  • CVE-2021-34565CriAug 31, 2021
    risk 0.64cvss 9.8epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

  • CVE-2020-12504CriOct 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3…

  • CVE-2020-12501CriOct 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

  • CVE-2020-12500CriOct 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.

  • CVE-2020-12511HigJan 22, 2021
    risk 0.57cvss 8.8epss 0.01

    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.

  • CVE-2020-12502HigOct 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3…

  • CVE-2021-20988HigMay 13, 2021
    risk 0.56cvss 8.6epss 0.01

    In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.

  • CVE-2021-20987HigFeb 16, 2021
    risk 0.56cvss 8.6epss 0.01

    A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.

  • CVE-2020-12513HigJan 22, 2021
    risk 0.51cvss 7.5epss 0.31

    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.

  • CVE-2024-6421HigJul 10, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

  • CVE-2021-34561HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying…

  • CVE-2021-33555HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.

  • CVE-2021-20986HigFeb 16, 2021
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.

  • CVE-2020-12512HigJan 22, 2021
    risk 0.49cvss 7.5epss 0.01

    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting

  • CVE-2020-12503HigOct 15, 2020
    risk 0.49cvss 7.2epss 0.23

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3…

  • CVE-2020-12525HigJan 22, 2021
    risk 0.48cvss 7.3epss 0.01

    M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

  • CVE-2024-38502HigAug 13, 2024
    risk 0.46cvss 7.1epss 0.00

    An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

  • CVE-2020-12514MedJan 22, 2021
    risk 0.43cvss 6.6epss 0.01

    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd

  • CVE-2024-38501MedAug 13, 2024
    risk 0.40cvss 6.1epss 0.00

    An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.