CVE-2026-27546
CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…
Vulnerabilità · 4 ore fa
Nozomi Networks Labs ha trovato 19 vulnerabilità nel Pepperl+Fuchs IO-Link Master ICE2-8IOL-K45P-RJ45 con firmware EtherNet/IP 1.7.3. Tra queste, una auth bypass può dare a un attaccante raggiungibile in rete una sessione admin senza credenziali valide, e altre falle consentono root command injection.
Il punto non è solo l’accesso al dispositivo. Questo IO-Link Master sta tra sensori e attuatori di campo e i sistemi OT superiori; con una sessione amministrativa un attaccante può cambiare configurazioni, falsare letture, inviare comandi agli attuatori o usare il gateway come trampolino verso altri sistemi industriali. Pepperl+Fuchs ha corretto i problemi con disclosure coordinata e CERT@VDE ha pubblicato un advisory.
Per chi gestisce ambienti manufacturing e infrastrutture critiche, resta un rischio da patch immediata: un’apparente anomalia della web interface può diventare controllo persistente del ponte tra campo e rete OT, non un guasto isolato di un singolo appliance.
CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the…
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by…
CVSS 7.5 HIGH: an unauthenticated remote attacker can exploit a path traversal vulnerability in the…
CVSS 7.2 HIGH: a high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint…
1 fonte che coprono questa storia
New Nozomi research identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks.
Part of the PlainSec briefing for 2026-09-29