Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Pepperl-fuchs
Subscribe
|
Io-link Master 4-eip
Subscribe
Io-link Master 4-eip Firmware
Subscribe
Io-link Master 4-pnio
Subscribe
Io-link Master 4-pnio Firmware
Subscribe
Io-link Master 8-eip
Subscribe
Io-link Master 8-eip-l
Subscribe
Io-link Master 8-eip-l Firmware
Subscribe
Io-link Master 8-eip Firmware
Subscribe
Io-link Master 8-pnio
Subscribe
Io-link Master 8-pnio-l
Subscribe
Io-link Master 8-pnio-l Firmware
Subscribe
Io-link Master 8-pnio Firmware
Subscribe
Io-link Master Dr-8-eip
Subscribe
Io-link Master Dr-8-eip-p
Subscribe
Io-link Master Dr-8-eip-p Firmware
Subscribe
Io-link Master Dr-8-eip-t
Subscribe
Io-link Master Dr-8-eip-t Firmware
Subscribe
Io-link Master Dr-8-eip Firmware
Subscribe
Io-link Master Dr-8-pnio
Subscribe
Io-link Master Dr-8-pnio-p
Subscribe
Io-link Master Dr-8-pnio-p Firmware
Subscribe
Io-link Master Dr-8-pnio-t
Subscribe
Io-link Master Dr-8-pnio-t Firmware
Subscribe
Io-link Master Dr-8-pnio Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4813 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface. |
Fixes
Solution
In order to prevent the exploitation of the reported vulnerabilities, we recommend that the affected units be updated with the following three firmware packages: U-Boot bootloader version 1.36 or newer System image version 1.52 or newer Application base version 1.6.11 or newer
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en-us/advisories/vde-2020-038 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-17T01:12:08.951Z
Reserved: 2020-04-30T00:00:00
Link: CVE-2020-12511
No data.
Status : Modified
Published: 2021-01-22T19:15:11.880
Modified: 2024-11-21T04:59:50.303
Link: CVE-2020-12511
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD