PT-2021-9459 · Pepperl+Fuchs · Pepperl+Fuchs Comtrol Io-Link Master

Published

2021-01-22

·

Updated

2021-01-27

·

CVE-2020-12511

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pepperl+Fuchs Comtrol IO-Link Master versions 1.5.48 and below
Description The issue is related to a Cross-Site Request Forgery (CSRF) in the web interface. This means an attacker could potentially trick a user into performing unintended actions on the web application.
Recommendations For versions 1.5.48 and below, consider disabling access to the web interface until a fix is available. Restrict access to the web interface to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12511

Affected Products

Pepperl+Fuchs Comtrol Io-Link Master