gsd-2020-12501
Vulnerability from gsd
Modified
2023-12-13 01:21
Details
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.
Aliases
Aliases



{
  "GSD": {
    "alias": "CVE-2020-12501",
    "description": "Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.",
    "id": "GSD-2020-12501",
    "references": [
      "https://packetstormsecurity.com/files/cve/CVE-2020-12501"
    ]
  },
  "gsd": {
    "metadata": {
      "exploitCode": "unknown",
      "remediation": "unknown",
      "reportConfidence": "confirmed",
      "type": "vulnerability"
    },
    "osvSchema": {
      "aliases": [
        "CVE-2020-12501"
      ],
      "details": "Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.",
      "id": "GSD-2020-12501",
      "modified": "2023-12-13T01:21:49.790965Z",
      "schema_version": "1.4.0"
    }
  },
  "namespaces": {
    "cve.org": {
      "CVE_data_meta": {
        "ASSIGNER": "info@cert.vde.com",
        "DATE_PUBLIC": "2020-10-07T13:10:00.000Z",
        "ID": "CVE-2020-12501",
        "STATE": "PUBLIC",
        "TITLE": "Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products"
      },
      "affects": {
        "vendor": {
          "vendor_data": [
            {
              "product": {
                "product_data": [
                  {
                    "product_name": "P+F Comtrol RocketLinx",
                    "version": {
                      "version_data": [
                        {
                          "version_affected": "=",
                          "version_name": "ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F,  ES8510-XTE, ES9528/ES9528-XT",
                          "version_value": "all"
                        },
                        {
                          "version_affected": "\u003c",
                          "version_name": "ES7510-XT",
                          "version_value": "2.1.1"
                        },
                        {
                          "version_affected": "\u003c",
                          "version_name": "ES8510",
                          "version_value": "3.1.1"
                        }
                      ]
                    }
                  }
                ]
              },
              "vendor_name": "Pepperl+Fuchs"
            },
            {
              "product": {
                "product_data": [
                  {
                    "product_name": "JetNet",
                    "version": {
                      "version_data": [
                        {
                          "version_affected": "\u003c=",
                          "version_name": "5428G-20SFP",
                          "version_value": "V1.0"
                        },
                        {
                          "version_affected": "\u003c=",
                          "version_name": "5810G",
                          "version_value": "V1.1"
                        },
                        {
                          "version_affected": "\u003c=",
                          "version_name": "4706F",
                          "version_value": "V2.3b"
                        },
                        {
                          "version_affected": "\u003c=",
                          "version_name": "4510",
                          "version_value": "V3.0b"
                        },
                        {
                          "version_affected": "\u003c",
                          "version_name": "5310",
                          "version_value": "V1.6"
                        }
                      ]
                    }
                  }
                ]
              },
              "vendor_name": "Korenix"
            },
            {
              "product": {
                "product_data": [
                  {
                    "product_name": "PMI-110-F2G",
                    "version": {
                      "version_data": [
                        {
                          "version_affected": "\u003c",
                          "version_value": "V1.8"
                        }
                      ]
                    }
                  }
                ]
              },
              "vendor_name": "Westermo"
            }
          ]
        }
      },
      "credit": [
        {
          "lang": "eng",
          "value": "T. Weber (SEC Consult Vulnerability Lab)"
        },
        {
          "lang": "eng",
          "value": "Coordinated by CERT@VDE"
        }
      ],
      "data_format": "MITRE",
      "data_type": "CVE",
      "data_version": "4.0",
      "description": {
        "description_data": [
          {
            "lang": "eng",
            "value": "Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts."
          }
        ]
      },
      "generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "impact": {
        "cvss": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        }
      },
      "problemtype": {
        "problemtype_data": [
          {
            "description": [
              {
                "lang": "eng",
                "value": "CWE-798 Use of Hard-coded Credentials"
              }
            ]
          }
        ]
      },
      "references": {
        "reference_data": [
          {
            "name": "https://cert.vde.com/de-de/advisories/vde-2020-040",
            "refsource": "CONFIRM",
            "url": "https://cert.vde.com/de-de/advisories/vde-2020-040"
          },
          {
            "name": "20210601 SEC Consult SA-20210601-0 :: Multiple critical vulnerabilities in Korenix Technology JetNet Series",
            "refsource": "FULLDISC",
            "url": "http://seclists.org/fulldisclosure/2021/Jun/0"
          },
          {
            "name": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html",
            "refsource": "MISC",
            "url": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html"
          },
          {
            "name": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/",
            "refsource": "CONFIRM",
            "url": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/"
          },
          {
            "name": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html",
            "refsource": "MISC",
            "url": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html"
          },
          {
            "name": "20220603 SEC Consult SA-20220531-0 :: Backdoor account in Korenix JetPort 5601V3",
            "refsource": "FULLDISC",
            "url": "http://seclists.org/fulldisclosure/2022/Jun/3"
          },
          {
            "name": "http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html",
            "refsource": "MISC",
            "url": "http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html"
          }
        ]
      },
      "solution": [
        {
          "lang": "eng",
          "value": "An external protective measure is required.\n\n1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially\ntraffic targeting the administration webpage.\n\n2) Administrator and user access should be protected by a secure password and only be\navailable to a very limited group of people."
        }
      ],
      "source": {
        "advisory": "VDE-2020-040",
        "discovery": "EXTERNAL"
      }
    },
    "nvd.nist.gov": {
      "cve": {
        "configurations": [
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es7510-xt_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "69279E51-1B3D-40F1-BC05-E7DE4FCF81D0",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es7510-xt:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E3FA814F-1C0E-4400-AA54-62520BD62F49",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es8509-xt_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "235B73CF-E9EE-46BC-A89F-A27EC816420F",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es8509-xt:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "663998ED-61CC-40CE-A580-4D40E28FA5DB",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es8510-xt_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "EEE2FFF7-9BEC-4456-9659-F1BC3E72508C",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es8510-xt:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "CF4AB5DA-CFEB-4F15-948D-1B5E08ADB370",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es9528-xtv2_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "8DFE9808-FA4D-4D8D-836D-7896ABD4DB6F",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es9528-xtv2:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "B1B6AD07-2B10-4B56-A08E-D9DBF98FF06E",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es7506_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "0BAB2AE4-E231-4485-89D3-4B153E7DFA60",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es7506:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "7CA6817C-7F79-42D9-BD4A-87B9278EE005",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es7510_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "9A81A766-C11C-4F1F-8D6D-66DA1067D04A",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es7510:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "F5AC80E6-5276-4209-8C11-889A88547934",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es7528_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "08F78AC1-DD60-4035-A573-1FBC94BC2CFB",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es7528:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "B0EF18AA-0305-48E6-BA3E-0921AAFAD21A",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es8508_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "F83E1070-A455-46A2-B677-1C55B78A872A",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es8508:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "35D1152B-2CC1-47CB-967C-450E54AA0AC2",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es8508f_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "679D27C7-C1AD-4B5F-9EF6-8559EDC48190",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es8508f:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E2AB75DB-57CA-49C5-86AB-75D766F23D24",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es8510_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "44ECCFCA-EE3D-4E66-BFB9-D5DC2CBBCB69",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es8510:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "8C58A4C3-2DD2-4B24-8C16-806041276486",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es8510-xte_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "EB4475C9-C8B6-4BE7-9DEC-4E3BD3616711",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es8510-xte:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "89EB4DB0-519A-47DD-B1A5-AD50071DD045",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es9528_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "F8B014C8-A75E-4A84-BB99-183CC44EB090",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es9528:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "5942FAF3-99D9-421A-92E3-5CA16A5B3E5F",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:pepperl-fuchs:es9528-xt_firmware:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "EF77744F-88F7-44E9-AA5C-7D0F0B664FAC",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:pepperl-fuchs:es9528-xt:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "F3F2C76E-3724-4626-B25E-EBCF5FE74C90",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetnet5428g-20sfp_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "A39B7395-45AF-4EB3-985C-44CDADD11922",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetnet_5428g-20sfp:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "41A504D7-8B61-4D78-9D66-9687D6110F47",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetnet5810g_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "A3D2B98A-96AF-41B0-9936-D6B4D5D6B3DC",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetnet_5810g:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "6C6C2282-D4E5-40FC-9C1A-749C1B1C623A",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetnet4510_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "9DA08A63-8E2D-4759-9650-BDFF7DDFAC15",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetnet_4510:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "C864A6A1-5E58-4EFE-85FC-DEDFBBC36473",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetnet5010_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "64895AB7-F14C-4602-B75C-FCCAC959C257",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetnet_5010:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "0896AC09-3022-4A14-93DB-D6BE6795C615",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetnet5310_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "269A98AD-D9FC-4EC3-93A4-F09BA545CEA7",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetnet_5310:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "86BE9095-B0A6-4268-AC78-453C462FB80B",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetnet6095_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "360E6861-48FD-49E2-BC65-C6D47E8B32D5",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetnet_6095:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "E5E6FE6C-873E-4C58-B590-3888BCE38F1D",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetnet4706_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "98ED84C6-2C50-40AE-9A44-1EFD1BA4202C",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetnet_4706:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "DD089EE1-3D71-430C-9CA9-BE32470BEE27",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetwave_3220_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "3F178611-DA1B-4279-9E72-5959B83F3AFE",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetwave_3220:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "D5B8C6FD-E29D-4207-9016-BD1ECCD81655",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetwave_2311_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "F195F448-A392-4DCA-8DC4-D1453873AB84",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetwave_2311:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "CFCA04DB-7738-4076-9D6B-22CE1C283806",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetnet4706f_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "A83AE7FC-AB5A-4886-A834-8063320F3D3A",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetnet_4706f:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "875F22D5-57B9-43EB-A92C-9FB0EA948164",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetwave_2212s_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "0B2ECE66-7592-4229-99DE-8FCF637D427E",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetwave_2212s:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "22491473-357B-4E88-9006-6688DCA38D67",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetwave_2212g_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "5C212D51-777C-40FE-A4BD-9FA6E760799E",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetwave_2212g:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "F8CF79B1-A8F9-4A3E-998A-8A7440659560",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          },
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:korenix:jetwave_2212x_firmware:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "70057501-308B-4D70-BD7E-C741AAAB0A82",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              },
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:h:korenix:jetwave_2212x:-:*:*:*:*:*:*:*",
                    "matchCriteriaId": "B1DB499F-F9EB-457F-9FFA-AAB262C503B9",
                    "vulnerable": false
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ],
            "operator": "AND"
          }
        ],
        "descriptions": [
          {
            "lang": "en",
            "value": "Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts."
          },
          {
            "lang": "es",
            "value": "Una vulnerabilidad de Autorizaci\u00f3n Inapropiada de Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528-XT (todas las versiones), utilizan cuentas no documentadas"
          }
        ],
        "id": "CVE-2020-12501",
        "lastModified": "2024-01-17T15:05:39.563",
        "metrics": {
          "cvssMetricV2": [
            {
              "acInsufInfo": false,
              "baseSeverity": "HIGH",
              "cvssData": {
                "accessComplexity": "LOW",
                "accessVector": "NETWORK",
                "authentication": "NONE",
                "availabilityImpact": "PARTIAL",
                "baseScore": 7.5,
                "confidentialityImpact": "PARTIAL",
                "integrityImpact": "PARTIAL",
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
                "version": "2.0"
              },
              "exploitabilityScore": 10.0,
              "impactScore": 6.4,
              "obtainAllPrivilege": false,
              "obtainOtherPrivilege": false,
              "obtainUserPrivilege": false,
              "source": "nvd@nist.gov",
              "type": "Primary",
              "userInteractionRequired": false
            }
          ],
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 3.9,
              "impactScore": 5.9,
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 3.9,
              "impactScore": 5.9,
              "source": "info@cert.vde.com",
              "type": "Secondary"
            }
          ]
        },
        "published": "2020-10-15T19:15:11.550",
        "references": [
          {
            "source": "info@cert.vde.com",
            "tags": [
              "Exploit",
              "Third Party Advisory",
              "VDB Entry"
            ],
            "url": "http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html"
          },
          {
            "source": "info@cert.vde.com",
            "tags": [
              "Exploit",
              "Third Party Advisory",
              "VDB Entry"
            ],
            "url": "http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html"
          },
          {
            "source": "info@cert.vde.com",
            "tags": [
              "Exploit",
              "Third Party Advisory"
            ],
            "url": "http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html"
          },
          {
            "source": "info@cert.vde.com",
            "tags": [
              "Mailing List",
              "Third Party Advisory"
            ],
            "url": "http://seclists.org/fulldisclosure/2021/Jun/0"
          },
          {
            "source": "info@cert.vde.com",
            "tags": [
              "Exploit",
              "Mailing List",
              "Third Party Advisory"
            ],
            "url": "http://seclists.org/fulldisclosure/2022/Jun/3"
          },
          {
            "source": "info@cert.vde.com",
            "tags": [
              "Third Party Advisory"
            ],
            "url": "https://cert.vde.com/de-de/advisories/vde-2020-040"
          },
          {
            "source": "info@cert.vde.com",
            "tags": [
              "Third Party Advisory"
            ],
            "url": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/"
          }
        ],
        "sourceIdentifier": "info@cert.vde.com",
        "vulnStatus": "Analyzed",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-798"
              }
            ],
            "source": "info@cert.vde.com",
            "type": "Primary"
          },
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-798"
              }
            ],
            "source": "nvd@nist.gov",
            "type": "Secondary"
          }
        ]
      }
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…