VYPR
Vendor

Pepperl+Fuchs

Products
15
CVEs
20
Across products
35
Status
Private

Products

15

Recent CVEs

20
  • CVE-2024-6422CriJul 10, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

  • CVE-2021-34565CriAug 31, 2021
    risk 0.64cvss 9.8epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

  • CVE-2020-12504CriOct 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3…

  • CVE-2020-12501CriOct 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

  • CVE-2020-12500CriOct 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.

  • CVE-2020-12502HigOct 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3…

  • CVE-2021-20988HigMay 13, 2021
    risk 0.56cvss 8.6epss 0.01

    In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.

  • CVE-2024-6421HigJul 10, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

  • CVE-2021-34561HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying…

  • CVE-2021-33555HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.

  • CVE-2020-12503HigOct 15, 2020
    risk 0.49cvss 7.2epss 0.23

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3…

  • CVE-2020-12525HigJan 22, 2021
    risk 0.48cvss 7.3epss 0.01

    M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

  • CVE-2024-5849HigAug 13, 2024
    risk 0.46cvss 7.1epss 0.00

    An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.

  • CVE-2024-38502HigAug 13, 2024
    risk 0.46cvss 7.1epss 0.00

    An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

  • CVE-2024-38501MedAug 13, 2024
    risk 0.40cvss 6.1epss 0.00

    An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.

  • CVE-2021-34564MedAug 31, 2021
    risk 0.36cvss 5.5epss 0.00

    Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.

  • CVE-2021-34560MedAug 31, 2021
    risk 0.36cvss 5.5epss 0.00

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.

  • CVE-2021-34562MedAug 31, 2021
    risk 0.35cvss 5.4epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.

  • CVE-2021-34559MedAug 31, 2021
    risk 0.35cvss 5.4epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.

  • CVE-2021-34563LowAug 31, 2021
    risk 0.21cvss 3.3epss 0.00

    In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.