CVE-2020-12504

Summary

CVECVE-2020-12504
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2020-10-15 19:15:00 UTC
Updated2022-03-16 14:02:00 UTC
DescriptionImproper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

Risk And Classification

Problem Types: CWE-912

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Korenix Jetwave 2212g - All All All
Operating System Korenix Jetwave 2212g Firmware 1.4 All All All
Hardware Korenix Jetwave 2212s - All All All
Operating System Korenix Jetwave 2212s Firmware 1.5 All All All
Hardware Korenix Jetwave 2212x - All All All
Operating System Korenix Jetwave 2212x Firmware 1.5 All All All
Hardware Korenix Jetwave 2311 - All All All
Operating System Korenix Jetwave 2311 Firmware 1.2 All All All
Hardware Korenix Jetwave 3220 - All All All
Operating System Korenix Jetwave 3220 Firmware 1.2 All All All
Hardware Korenix Jetwave 3420 - All All All
Operating System Korenix Jetwave 3420 Firmware 1.1.3t All All All
Hardware Korenix Jetwave 4510 - All All All
Operating System Korenix Jetwave 4510 Firmware 3.0b All All All
Hardware Korenix Jetwave 4706 - All All All
Hardware Korenix Jetwave 4706f - All All All
Operating System Korenix Jetwave 4706f Firmware 2.3b All All All
Operating System Korenix Jetwave 4706 Firmware 2.3b All All All
Hardware Korenix Jetwave 5010 - All All All
Operating System Korenix Jetwave 5010 Firmware 3.1a All All All
Hardware Korenix Jetwave 5310 - All All All
Operating System Korenix Jetwave 5310 Firmware 1.5 All All All
Hardware Korenix Jetwave 5428g-20sfp - All All All
Operating System Korenix Jetwave 5428g-20sfp Firmware 1.0 All All All
Hardware Korenix Jetwave 5810g - All All All
Operating System Korenix Jetwave 5810g Firmware 1.1 All All All
Hardware Pepperl-fuchs Es7506 - All All All
Hardware Pepperl-fuchs Es7506 - All All All
Operating System Pepperl-fuchs Es7506 Firmware All All All All
Operating System Pepperl-fuchs Es7506 Firmware All All All All
Hardware Pepperl-fuchs Es7510 - All All All
Hardware Pepperl-fuchs Es7510 - All All All
Hardware Pepperl-fuchs Es7510-xt - All All All
Hardware Pepperl-fuchs Es7510-xt - All All All
Operating System Pepperl-fuchs Es7510-xt Firmware All All All All
Operating System Pepperl-fuchs Es7510-xt Firmware All All All All
Operating System Pepperl-fuchs Es7510 Firmware All All All All
Operating System Pepperl-fuchs Es7510 Firmware All All All All
Hardware Pepperl-fuchs Es7528 - All All All
Hardware Pepperl-fuchs Es7528 - All All All
Operating System Pepperl-fuchs Es7528 Firmware All All All All
Operating System Pepperl-fuchs Es7528 Firmware All All All All
Hardware Pepperl-fuchs Es8508 - All All All
Hardware Pepperl-fuchs Es8508 - All All All
Hardware Pepperl-fuchs Es8508f - All All All
Hardware Pepperl-fuchs Es8508f - All All All
Operating System Pepperl-fuchs Es8508f Firmware All All All All
Operating System Pepperl-fuchs Es8508f Firmware All All All All
Operating System Pepperl-fuchs Es8508 Firmware All All All All
Operating System Pepperl-fuchs Es8508 Firmware All All All All
Hardware Pepperl-fuchs Es8509-xt - All All All
Hardware Pepperl-fuchs Es8509-xt - All All All
Operating System Pepperl-fuchs Es8509-xt Firmware All All All All
Operating System Pepperl-fuchs Es8509-xt Firmware All All All All
Hardware Pepperl-fuchs Es8510 - All All All
Hardware Pepperl-fuchs Es8510 - All All All
Hardware Pepperl-fuchs Es8510-xt - All All All
Hardware Pepperl-fuchs Es8510-xt - All All All
Hardware Pepperl-fuchs Es8510-xte - All All All
Hardware Pepperl-fuchs Es8510-xte - All All All
Operating System Pepperl-fuchs Es8510-xte Firmware All All All All
Operating System Pepperl-fuchs Es8510-xte Firmware All All All All
Operating System Pepperl-fuchs Es8510-xt Firmware All All All All
Operating System Pepperl-fuchs Es8510-xt Firmware All All All All
Operating System Pepperl-fuchs Es8510 Firmware All All All All
Operating System Pepperl-fuchs Es8510 Firmware All All All All
Hardware Pepperl-fuchs Es9528 - All All All
Hardware Pepperl-fuchs Es9528 - All All All
Hardware Pepperl-fuchs Es9528-xt - All All All
Hardware Pepperl-fuchs Es9528-xt - All All All
Hardware Pepperl-fuchs Es9528-xtv2 - All All All
Hardware Pepperl-fuchs Es9528-xtv2 - All All All
Operating System Pepperl-fuchs Es9528-xtv2 Firmware All All All All
Operating System Pepperl-fuchs Es9528-xtv2 Firmware All All All All
Operating System Pepperl-fuchs Es9528-xt Firmware All All All All
Operating System Pepperl-fuchs Es9528-xt Firmware All All All All
Operating System Pepperl-fuchs Es9528 Firmware All All All All
Operating System Pepperl-fuchs Es9528 Firmware All All All All
Hardware Pepperl-fuchs Icrl-m-16rj45/4cp-g-din - All All All
Hardware Pepperl-fuchs Icrl-m-16rj45/4cp-g-din - All All All
Operating System Pepperl-fuchs Icrl-m-16rj45/4cp-g-din Firmware All All All All
Operating System Pepperl-fuchs Icrl-m-16rj45/4cp-g-din Firmware All All All All
Hardware Pepperl-fuchs Icrl-m-8rj45/4sfp-g-din - All All All
Hardware Pepperl-fuchs Icrl-m-8rj45/4sfp-g-din - All All All
Operating System Pepperl-fuchs Icrl-m-8rj45/4sfp-g-din Firmware All All All All
Operating System Pepperl-fuchs Icrl-m-8rj45/4sfp-g-din Firmware All All All All
Hardware Westermo Pmi-110-f2g - All All All
Operating System Westermo Pmi-110-f2g Firmware 1.5 All All All

References

ReferenceSourceLinkTags
PEPPERL+FUCHS: Multiple Products prone to multiple vulnerabilities in Comtrol RocketLinux (Update A) — German (Germany) CONFIRM cert.vde.com Third Party Advisory
Korenix CSRF / Backdoor Accounts / Command Injection / Missing Authentication ≈ Packet Storm MISC packetstormsecurity.com
Full Disclosure: SEC Consult SA-20210601-0 :: Multiple critical vulnerabilities in Korenix Technology JetNet Series FULLDISC seclists.org
Multiple Critical Vulnerabilities in Korenix Technology, Westermo and Pepperl+Fuchs products CONFIRM sec-consult.com
PEPPERL+FUCHS: Comtrol RocketLinx ICRL-M - Multiple Vulnerabilities — English (USA) CONFIRM cert.vde.com
Korenix Technology JetWave CSRF / Command Injection / Missing Authentication ≈ Packet Storm MISC packetstormsecurity.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

LEGACY: T. Weber (SEC Consult Vulnerability Lab)

LEGACY: Coordinated by CERT@VDE

© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report