PT-2020-13146 · Pepperl+Fuchs+1 · Pepperl+Fuchs P+F Comtrol Rocketlinx Es7506+8
T. Weber
+1
·
Published
2020-10-15
·
Updated
2024-01-17
·
CVE-2020-12501
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions)
Korenix JetPort 5601V3 (all versions)
Description
The issue concerns an Improper Authorization vulnerability where undocumented accounts are used. This vulnerability allows attackers to gain full control over devices. The problem is exacerbated by the fact that the backdoor account has the same password as the firmware, which cannot be changed by the user. This vulnerability has been known since 2012 and was previously addressed with a firmware update, but it has resurfaced. The vulnerability can be exploited to reconfigure devices and potentially gain access to other connected systems.
Recommendations
For Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions): At the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Korenix JetPort 5601V3 (all versions): Consider restricting access to the device until a patch is available, as the backdoor account cannot be removed or changed. Avoid using the undocumented account to prevent exploitation.
Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Korenix Jetport 5601V3
Pepperl+Fuchs P+F Comtrol Rocketlinx Es7506
Pepperl+Fuchs P+F Comtrol Rocketlinx Es7510
Pepperl+Fuchs P+F Comtrol Rocketlinx Es7528
Pepperl+Fuchs P+F Comtrol Rocketlinx Es8508
Pepperl+Fuchs P+F Comtrol Rocketlinx Es8509-Xt
Pepperl+Fuchs P+F Comtrol Rocketlinx Es8510
Pepperl+Fuchs P+F Comtrol Rocketlinx Es9528-Xtv2
Pepperl+Fuchs P+F Comtrol Rocketlinx Es9528/Es9528-Xt