PT-2021-9459 · Pepperl+Fuchs · Pepperl+Fuchs Comtrol Io-Link Master
Published
2021-01-22
·
Updated
2021-01-27
·
CVE-2020-12511
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pepperl+Fuchs Comtrol IO-Link Master versions 1.5.48 and below
Description
The issue is related to a Cross-Site Request Forgery (CSRF) in the web interface. This means an attacker could potentially trick a user into performing unintended actions on the web application.
Recommendations
For versions 1.5.48 and below, consider disabling access to the web interface until a fix is available. Restrict access to the web interface to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pepperl+Fuchs Comtrol Io-Link Master