CVE-2020-12501
9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.34% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-10-15 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| korenix | jetnet 4510 |
| korenix | jetnet 4706 |
| korenix | jetnet 5010 |
| korenix | jetnet 5310 |
| korenix | jetnet 5428g-20sfp |
| korenix | jetnet 5810g |
| korenix | jetnet 6095 |
| korenix | jetnet4510 firmware |
| korenix | jetnet4706 firmware |
| korenix | jetnet5010 firmware |
| korenix | jetnet5310 firmware |
| korenix | jetnet5428g-20sfp firmware |
| korenix | jetnet5810g firmware |
| korenix | jetnet6095 firmware |
| pepperl-fuchs | es7506 |
| pepperl-fuchs | es7506 firmware |
| pepperl-fuchs | es7510 |
| pepperl-fuchs | es7510 firmware |
| pepperl-fuchs | es7510-xt |
| pepperl-fuchs | es7510-xt firmware |
| pepperl-fuchs | es7528 |
| pepperl-fuchs | es7528 firmware |
| pepperl-fuchs | es8508 |
| pepperl-fuchs | es8508 firmware |
| pepperl-fuchs | es8508f |
| pepperl-fuchs | es8508f firmware |
| pepperl-fuchs | es8509-xt |
| pepperl-fuchs | es8509-xt firmware |
| pepperl-fuchs | es8510 |
| pepperl-fuchs | es8510 firmware |
| pepperl-fuchs | es8510-xt |
| pepperl-fuchs | es8510-xt firmware |
| pepperl-fuchs | es8510-xte |
| pepperl-fuchs | es8510-xte firmware |
| pepperl-fuchs | es9528 |
| pepperl-fuchs | es9528 firmware |
| pepperl-fuchs | es9528-xt |
| pepperl-fuchs | es9528-xt firmware |
| pepperl-fuchs | es9528-xtv2 |
| pepperl-fuchs | es9528-xtv2 firmware |
References
- http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html
- http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html
- http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html
- http://seclists.org/fulldisclosure/2021/Jun/0
- http://seclists.org/fulldisclosure/2022/Jun/3
- https://cert.vde.com/de-de/advisories/vde-2020-040
- https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/
- http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html
- http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html
- http://packetstormsecurity.com/files/167409/Korenix-JetPort-5601V3-Backdoor-Account.html
- http://seclists.org/fulldisclosure/2021/Jun/0
- http://seclists.org/fulldisclosure/2022/Jun/3
- https://cert.vde.com/de-de/advisories/vde-2020-040
- https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/
→ the Explorer · watch your stack · NVD