CVE-2020-12501 (GCVE-0-2020-12501)
Vulnerability from cvelistv5
Published
2020-10-15 18:42
Modified
2024-09-16 19:20
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-798 - Use of Hard-coded Credentials
Summary
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.
References
Impacted products
Vendor | Product | Version | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Pepperl+Fuchs | P+F Comtrol RocketLinx |
Version: ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510-XTE, ES9528/ES9528-XT all Version: ES7510-XT < 2.1.1 Version: ES8510 < 3.1.1 |
|||||||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T11:56:52.091Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://cert.vde.com/de-de/advisories/vde-2020-040" }, { "name": "20210601 SEC Consult SA-20210601-0 :: Multiple critical vulnerabilities in Korenix Technology JetNet Series", "tags": [ "mailing-list", "x_refsource_FULLDISC", "x_transferred" ], "url": "http://seclists.org/fulldisclosure/2021/Jun/0" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html" }, { "name": "20220603 SEC Consult SA-20220531-0 :: Backdoor account in Korenix JetPort 5601V3", "tags": [ "mailing-list", "x_refsource_FULLDISC", "x_transferred" ], "url": "http://seclists.org/fulldisclosure/2022/Jun/3" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "P+F Comtrol RocketLinx", "vendor": "Pepperl+Fuchs", "versions": [ { "status": "affected", "version": "ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510-XTE, ES9528/ES9528-XT all" }, { "lessThan": "2.1.1", "status": "affected", "version": "ES7510-XT", "versionType": "custom" }, { "lessThan": "3.1.1", "status": "affected", "version": "ES8510", "versionType": "custom" } ] }, { "product": "JetNet", "vendor": "Korenix", "versions": [ { "lessThanOrEqual": "V1.0", "status": "affected", "version": "5428G-20SFP", "versionType": "custom" }, { "lessThanOrEqual": "V1.1", "status": "affected", "version": "5810G", "versionType": "custom" }, { "lessThanOrEqual": "V2.3b", "status": "affected", "version": "4706F", "versionType": "custom" }, { "lessThanOrEqual": "V3.0b", "status": "affected", "version": "4510", "versionType": "custom" }, { "lessThan": "V1.6", "status": "affected", "version": "5310", "versionType": "custom" } ] }, { "product": "PMI-110-F2G", "vendor": "Westermo", "versions": [ { "lessThan": "V1.8", "status": "affected", "version": "unspecified", "versionType": "custom" } ] } ], "credits": [ { "lang": "en", "value": "T. Weber (SEC Consult Vulnerability Lab)" }, { "lang": "en", "value": "Coordinated by CERT@VDE" } ], "datePublic": "2020-10-07T00:00:00", "descriptions": [ { "lang": "en", "value": "Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-798", "description": "CWE-798 Use of Hard-coded Credentials", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2022-06-06T16:06:23", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "https://cert.vde.com/de-de/advisories/vde-2020-040" }, { "name": "20210601 SEC Consult SA-20210601-0 :: Multiple critical vulnerabilities in Korenix Technology JetNet Series", "tags": [ "mailing-list", "x_refsource_FULLDISC" ], "url": "http://seclists.org/fulldisclosure/2021/Jun/0" }, { "tags": [ "x_refsource_MISC" ], "url": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/" }, { "tags": [ "x_refsource_MISC" ], "url": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html" }, { "name": "20220603 SEC Consult SA-20220531-0 :: Backdoor account in Korenix JetPort 5601V3", "tags": [ "mailing-list", "x_refsource_FULLDISC" ], "url": "http://seclists.org/fulldisclosure/2022/Jun/3" }, { "tags": [ "x_refsource_MISC" ], "url": "http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html" } ], "solutions": [ { "lang": "en", "value": "An external protective measure is required.\n\n1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially\ntraffic targeting the administration webpage.\n\n2) Administrator and user access should be protected by a secure password and only be\navailable to a very limited group of people." } ], "source": { "advisory": "VDE-2020-040", "discovery": "EXTERNAL" }, "title": "Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products", "x_generator": { "engine": "Vulnogram 0.0.9" }, "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "info@cert.vde.com", "DATE_PUBLIC": "2020-10-07T13:10:00.000Z", "ID": "CVE-2020-12501", "STATE": "PUBLIC", "TITLE": "Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "P+F Comtrol RocketLinx", "version": { "version_data": [ { "version_affected": "=", "version_name": "ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510-XTE, ES9528/ES9528-XT", "version_value": "all" }, { "version_affected": "\u003c", "version_name": "ES7510-XT", "version_value": "2.1.1" }, { "version_affected": "\u003c", "version_name": "ES8510", "version_value": "3.1.1" } ] } } ] }, "vendor_name": "Pepperl+Fuchs" }, { "product": { "product_data": [ { "product_name": "JetNet", "version": { "version_data": [ { "version_affected": "\u003c=", "version_name": "5428G-20SFP", "version_value": "V1.0" }, { "version_affected": "\u003c=", "version_name": "5810G", "version_value": "V1.1" }, { "version_affected": "\u003c=", "version_name": "4706F", "version_value": "V2.3b" }, { "version_affected": "\u003c=", "version_name": "4510", "version_value": "V3.0b" }, { "version_affected": "\u003c", "version_name": "5310", "version_value": "V1.6" } ] } } ] }, "vendor_name": "Korenix" }, { "product": { "product_data": [ { "product_name": "PMI-110-F2G", "version": { "version_data": [ { "version_affected": "\u003c", "version_value": "V1.8" } ] } } ] }, "vendor_name": "Westermo" } ] } }, "credit": [ { "lang": "eng", "value": "T. Weber (SEC Consult Vulnerability Lab)" }, { "lang": "eng", "value": "Coordinated by CERT@VDE" } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts." } ] }, "generator": { "engine": "Vulnogram 0.0.9" }, "impact": { "cvss": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-798 Use of Hard-coded Credentials" } ] } ] }, "references": { "reference_data": [ { "name": "https://cert.vde.com/de-de/advisories/vde-2020-040", "refsource": "CONFIRM", "url": "https://cert.vde.com/de-de/advisories/vde-2020-040" }, { "name": "20210601 SEC Consult SA-20210601-0 :: Multiple critical vulnerabilities in Korenix Technology JetNet Series", "refsource": "FULLDISC", "url": "http://seclists.org/fulldisclosure/2021/Jun/0" }, { "name": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html", "refsource": "MISC", "url": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html" }, { "name": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/", "refsource": "CONFIRM", "url": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/" }, { "name": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html", "refsource": "MISC", "url": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html" }, { "name": "20220603 SEC Consult SA-20220531-0 :: Backdoor account in Korenix JetPort 5601V3", "refsource": "FULLDISC", "url": "http://seclists.org/fulldisclosure/2022/Jun/3" }, { "name": "http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html", "refsource": "MISC", "url": "http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html" } ] }, "solution": [ { "lang": "en", "value": "An external protective measure is required.\n\n1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially\ntraffic targeting the administration webpage.\n\n2) Administrator and user access should be protected by a secure password and only be\navailable to a very limited group of people." } ], "source": { "advisory": "VDE-2020-040", "discovery": "EXTERNAL" } } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2020-12501", "datePublished": "2020-10-15T18:42:56.306067Z", "dateReserved": "2020-04-30T00:00:00", "dateUpdated": "2024-09-16T19:20:40.911Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2020-12501\",\"sourceIdentifier\":\"info@cert.vde.com\",\"published\":\"2020-10-15T19:15:11.550\",\"lastModified\":\"2024-11-21T04:59:48.783\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.\"},{\"lang\":\"es\",\"value\":\"Una vulnerabilidad de Autorizaci\u00f3n Inapropiada de Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528-XT (todas las versiones), utilizan cuentas no documentadas\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"info@cert.vde.com\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\"baseScore\":9.8,\"baseSeverity\":\"CRITICAL\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"HIGH\"},\"exploitabilityScore\":3.9,\"impactScore\":5.9},{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\"baseScore\":9.8,\"baseSeverity\":\"CRITICAL\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"HIGH\"},\"exploitabilityScore\":3.9,\"impactScore\":5.9}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:L/Au:N/C:P/I:P/A:P\",\"baseScore\":7.5,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"LOW\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"PARTIAL\",\"availabilityImpact\":\"PARTIAL\"},\"baseSeverity\":\"HIGH\",\"exploitabilityScore\":10.0,\"impactScore\":6.4,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"info@cert.vde.com\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-798\"}]},{\"source\":\"nvd@nist.gov\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-798\"}]}],\"configurations\":[{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es7510-xt_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"69279E51-1B3D-40F1-BC05-E7DE4FCF81D0\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es7510-xt:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"E3FA814F-1C0E-4400-AA54-62520BD62F49\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es8509-xt_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"235B73CF-E9EE-46BC-A89F-A27EC816420F\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es8509-xt:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"663998ED-61CC-40CE-A580-4D40E28FA5DB\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es8510-xt_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"EEE2FFF7-9BEC-4456-9659-F1BC3E72508C\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es8510-xt:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"CF4AB5DA-CFEB-4F15-948D-1B5E08ADB370\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es9528-xtv2_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"8DFE9808-FA4D-4D8D-836D-7896ABD4DB6F\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es9528-xtv2:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"B1B6AD07-2B10-4B56-A08E-D9DBF98FF06E\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es7506_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"0BAB2AE4-E231-4485-89D3-4B153E7DFA60\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es7506:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"7CA6817C-7F79-42D9-BD4A-87B9278EE005\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es7510_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"9A81A766-C11C-4F1F-8D6D-66DA1067D04A\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es7510:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F5AC80E6-5276-4209-8C11-889A88547934\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es7528_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"08F78AC1-DD60-4035-A573-1FBC94BC2CFB\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es7528:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"B0EF18AA-0305-48E6-BA3E-0921AAFAD21A\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es8508_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F83E1070-A455-46A2-B677-1C55B78A872A\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es8508:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"35D1152B-2CC1-47CB-967C-450E54AA0AC2\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es8508f_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"679D27C7-C1AD-4B5F-9EF6-8559EDC48190\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es8508f:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"E2AB75DB-57CA-49C5-86AB-75D766F23D24\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es8510_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"44ECCFCA-EE3D-4E66-BFB9-D5DC2CBBCB69\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es8510:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"8C58A4C3-2DD2-4B24-8C16-806041276486\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es8510-xte_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"EB4475C9-C8B6-4BE7-9DEC-4E3BD3616711\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es8510-xte:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"89EB4DB0-519A-47DD-B1A5-AD50071DD045\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es9528_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F8B014C8-A75E-4A84-BB99-183CC44EB090\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es9528:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"5942FAF3-99D9-421A-92E3-5CA16A5B3E5F\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:pepperl-fuchs:es9528-xt_firmware:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"EF77744F-88F7-44E9-AA5C-7D0F0B664FAC\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:pepperl-fuchs:es9528-xt:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F3F2C76E-3724-4626-B25E-EBCF5FE74C90\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetnet5428g-20sfp_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"A39B7395-45AF-4EB3-985C-44CDADD11922\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetnet_5428g-20sfp:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"41A504D7-8B61-4D78-9D66-9687D6110F47\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetnet5810g_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"A3D2B98A-96AF-41B0-9936-D6B4D5D6B3DC\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetnet_5810g:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"6C6C2282-D4E5-40FC-9C1A-749C1B1C623A\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetnet4510_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"9DA08A63-8E2D-4759-9650-BDFF7DDFAC15\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetnet_4510:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"C864A6A1-5E58-4EFE-85FC-DEDFBBC36473\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetnet5010_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"64895AB7-F14C-4602-B75C-FCCAC959C257\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetnet_5010:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"0896AC09-3022-4A14-93DB-D6BE6795C615\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetnet5310_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"269A98AD-D9FC-4EC3-93A4-F09BA545CEA7\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetnet_5310:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"86BE9095-B0A6-4268-AC78-453C462FB80B\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetnet6095_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"360E6861-48FD-49E2-BC65-C6D47E8B32D5\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetnet_6095:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"E5E6FE6C-873E-4C58-B590-3888BCE38F1D\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetnet4706_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"98ED84C6-2C50-40AE-9A44-1EFD1BA4202C\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetnet_4706:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"DD089EE1-3D71-430C-9CA9-BE32470BEE27\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetwave_3220_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"3F178611-DA1B-4279-9E72-5959B83F3AFE\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetwave_3220:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"D5B8C6FD-E29D-4207-9016-BD1ECCD81655\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetwave_2311_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F195F448-A392-4DCA-8DC4-D1453873AB84\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetwave_2311:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"CFCA04DB-7738-4076-9D6B-22CE1C283806\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetnet4706f_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"A83AE7FC-AB5A-4886-A834-8063320F3D3A\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetnet_4706f:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"875F22D5-57B9-43EB-A92C-9FB0EA948164\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetwave_2212s_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"0B2ECE66-7592-4229-99DE-8FCF637D427E\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetwave_2212s:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"22491473-357B-4E88-9006-6688DCA38D67\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetwave_2212g_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"5C212D51-777C-40FE-A4BD-9FA6E760799E\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetwave_2212g:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F8CF79B1-A8F9-4A3E-998A-8A7440659560\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:korenix:jetwave_2212x_firmware:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"70057501-308B-4D70-BD7E-C741AAAB0A82\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:korenix:jetwave_2212x:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"B1DB499F-F9EB-457F-9FFA-AAB262C503B9\"}]}]}],\"references\":[{\"url\":\"http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html\",\"source\":\"info@cert.vde.com\",\"tags\":[\"Exploit\",\"Third Party Advisory\",\"VDB Entry\"]},{\"url\":\"http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html\",\"source\":\"info@cert.vde.com\",\"tags\":[\"Exploit\",\"Third Party Advisory\",\"VDB Entry\"]},{\"url\":\"http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html\",\"source\":\"info@cert.vde.com\",\"tags\":[\"Exploit\",\"Third Party Advisory\"]},{\"url\":\"http://seclists.org/fulldisclosure/2021/Jun/0\",\"source\":\"info@cert.vde.com\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://seclists.org/fulldisclosure/2022/Jun/3\",\"source\":\"info@cert.vde.com\",\"tags\":[\"Exploit\",\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"https://cert.vde.com/de-de/advisories/vde-2020-040\",\"source\":\"info@cert.vde.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/\",\"source\":\"info@cert.vde.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\",\"Third Party Advisory\",\"VDB Entry\"]},{\"url\":\"http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\",\"Third Party Advisory\",\"VDB Entry\"]},{\"url\":\"http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\",\"Third Party Advisory\"]},{\"url\":\"http://seclists.org/fulldisclosure/2021/Jun/0\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://seclists.org/fulldisclosure/2022/Jun/3\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\",\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"https://cert.vde.com/de-de/advisories/vde-2020-040\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]}]}}" } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…