PT-2020-13146 · Pepperl+Fuchs+1 · Pepperl+Fuchs P+F Comtrol Rocketlinx Es7506+8

T. Weber

+1

·

Published

2020-10-15

·

Updated

2024-01-17

·

CVE-2020-12501

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) Korenix JetPort 5601V3 (all versions)
Description The issue concerns an Improper Authorization vulnerability where undocumented accounts are used. This vulnerability allows attackers to gain full control over devices. The problem is exacerbated by the fact that the backdoor account has the same password as the firmware, which cannot be changed by the user. This vulnerability has been known since 2012 and was previously addressed with a firmware update, but it has resurfaced. The vulnerability can be exploited to reconfigure devices and potentially gain access to other connected systems.
Recommendations For Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions): At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Korenix JetPort 5601V3 (all versions): Consider restricting access to the device until a patch is available, as the backdoor account cannot be removed or changed. Avoid using the undocumented account to prevent exploitation.

Exploit

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-12501

Affected Products

Korenix Jetport 5601V3
Pepperl+Fuchs P+F Comtrol Rocketlinx Es7506
Pepperl+Fuchs P+F Comtrol Rocketlinx Es7510
Pepperl+Fuchs P+F Comtrol Rocketlinx Es7528
Pepperl+Fuchs P+F Comtrol Rocketlinx Es8508
Pepperl+Fuchs P+F Comtrol Rocketlinx Es8509-Xt
Pepperl+Fuchs P+F Comtrol Rocketlinx Es8510
Pepperl+Fuchs P+F Comtrol Rocketlinx Es9528-Xtv2
Pepperl+Fuchs P+F Comtrol Rocketlinx Es9528/Es9528-Xt