4
CVSSv2

CVE-2020-12514

Published: 22/01/2021 Updated: 28/01/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pepperl-fuchs io-link_master_4-eip_firmware

pepperl-fuchs io-link_master_8-eip_firmware

pepperl-fuchs io-link_master_8-eip-l_firmware

pepperl-fuchs io-link_master_dr-8-eip_firmware

pepperl-fuchs io-link_master_dr-8-eip-p_firmware

pepperl-fuchs io-link_master_dr-8-eip-t_firmware

pepperl-fuchs io-link_master_4-pnio_firmware

pepperl-fuchs io-link_master_8-pnio_firmware

pepperl-fuchs io-link_master_8-pnio-l_firmware

pepperl-fuchs io-link_master_dr-8-pnio_firmware

pepperl-fuchs io-link_master_dr-8-pnio-p_firmware

pepperl-fuchs io-link_master_dr-8-pnio-t_firmware

Exploits

Pepperl+Fuchs IO-Link Master Series with system version 136 and application version 1528 suffers from command injection, cross site request forgery, cross site scripting, denial of service, and null pointer vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SEC Consult SA-20210113-0 :: Multiple vulnerabilities in Pepperl+Fuchs IO-Link Master Series <!--X-Subject-Header-End- ...