Vulnerabilità ed exploit · Attacco IoT / OT
Il gateway OT diventa un varco per prendere il controllo del processo Nozomi Networks Labs ha trovato 19 vulnerabilità nel Pepperl+Fuchs IO-Link Master ICE2 -8IOL-K45P-RJ45 con firmware EtherNet/IP 1.7.3 . Tra queste, una auth bypass può dare a un attaccante raggiungibile in rete una sessione admin senza credenziali valide, e altre falle consentono root command injection.
Il punto non è solo l’accesso al dispositivo. Questo IO-Link Master sta tra sensori e attuatori di campo e i sistemi OT superiori; con una sessione amministrativa un attaccante può cambiare configurazioni, falsare letture, inviare comandi agli attuatori o usare il gateway come trampolino verso altri sistemi industriali. Pepperl+Fuchs ha corretto i problemi con disclosure coordinata e CERT@VDE ha pubblicato un advisory.
Per chi gestisce ambienti manufacturing e infrastrutture critiche, resta un rischio da patch immediata: un’apparente anomalia della web interface può diventare controllo persistente del ponte tra campo e rete OT, non un guasto isolato di un singolo appliance.
1 fonte · 5 ore fa
CVE-2026-27546 NVD KEV
CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…
CVE-2026-27549 NVD KEV
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the…
CVE-2026-27559 NVD KEV
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by…
CVE-2026-27557 NVD KEV
CVSS 7.5 HIGH: an unauthenticated remote attacker can exploit a path traversal vulnerability in the…
CVE-2026-27564 NVD KEV
CVSS 7.2 HIGH: a high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint…
Cronologia Fonti 29 set Industrial Cyber
Nozomi identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks - Industrial Cyber
New Nozomi research identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks.
originale Part of the PlainSec briefing for 2026-09-29
Every edition of this story: Il gateway OT diventa un varco per prendere il controllo del processo
Altro da oggi
Vulnerabilità ed exploit · Attacco IoT / OT
Il gateway OT diventa un varco per prendere il controllo del processo Nozomi Networks Labs ha trovato 19 vulnerabilità nel Pepperl+Fuchs IO-Link Master ICE2 -8IOL-K45P-RJ45 con firmware EtherNet/IP 1.7.3 . Tra queste, una auth bypass può dare a un attaccante raggiungibile in rete una sessione admin senza credenziali valide, e altre falle consentono root command injection.
Il punto non è solo l’accesso al dispositivo. Questo IO-Link Master sta tra sensori e attuatori di campo e i sistemi OT superiori; con una sessione amministrativa un attaccante può cambiare configurazioni, falsare letture, inviare comandi agli attuatori o usare il gateway come trampolino verso altri sistemi industriali. Pepperl+Fuchs ha corretto i problemi con disclosure coordinata e CERT@VDE ha pubblicato un advisory.
Per chi gestisce ambienti manufacturing e infrastrutture critiche, resta un rischio da patch immediata: un’apparente anomalia della web interface può diventare controllo persistente del ponte tra campo e rete OT, non un guasto isolato di un singolo appliance.
1 fonte · 5 ore fa
CVE-2026-27546 NVD KEV
CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…
CVE-2026-27549 NVD KEV
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the…
CVE-2026-27559 NVD KEV
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by…
CVE-2026-27557 NVD KEV
CVSS 7.5 HIGH: an unauthenticated remote attacker can exploit a path traversal vulnerability in the…
CVE-2026-27564 NVD KEV
CVSS 7.2 HIGH: a high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint…
Cronologia Fonti 29 set Industrial Cyber
Nozomi identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks - Industrial Cyber
New Nozomi research identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks.
originale Part of the PlainSec briefing for 2026-09-29
Every edition of this story: Il gateway OT diventa un varco per prendere il controllo del processo
Altro da oggi