#VU47406 Use of hard-coded credentials in PEPPERL+FUCHS products - CVE-2020-12501

 

#VU47406 Use of hard-coded credentials in PEPPERL+FUCHS products - CVE-2020-12501

Published: October 7, 2020


Vulnerability identifier: #VU47406
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-12501
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
RocketLinx ES7510-XT
RocketLinx ES8509-XT
RocketLinx ES8510-XT
RocketLinx ES9528-XTv2
RocketLinx ES7506
RocketLinx ES7510
RocketLinx ES7528
RocketLinx ES8508
RocketLinx ES8508F
RocketLinx ES8510
RocketLinx ES8510-XTE
RocketLinx ES9528/ES9528-XT
Software vendor:
PEPPERL+FUCHS

Description

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded credentials in application code. A remote unauthenticated attacker can access the affected system using the hard-coded credentials.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable syste


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links