Risk Scores
CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.55%
67.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Korenix | JetNet | 5810G, 5310, 4510 |
| pepperl-fuchs | es7528_firmware | |
| korenix | jetwave_5428g-20sfp_firmware | 1.0 |
| korenix | jetwave_2212x_firmware | 1.5 |
| westermo | pmi-110-f2g_firmware | 1.5 |
| pepperl-fuchs | es9528-xtv2_firmware | |
| korenix | jetwave_3220_firmware | 1.2 |
| pepperl-fuchs | es7510-xt_firmware | 0 |
| pepperl-fuchs | es8510-xt_firmware | |
| korenix | jetwave_4706_firmware | 2.3b |
| korenix | jetwave_4706f_firmware | 2.3b |
| korenix | jetwave_5810g_firmware | 1.1 |
| pepperl-fuchs | es8508f_firmware | |
| pepperl-fuchs | es9528-xt_firmware | |
| pepperl-fuchs | es8509-xt_firmware | |
| pepperl-fuchs | icrl-m-16rj45\/4cp-g-din_firmware | 0 |
| pepperl-fuchs | es8508_firmware | |
| Pepperl+Fuchs | P+F Comtrol RocketLinx | ICRL-M-8RJ45/4SFP-G-DIN, ES8510, ICRL-M-16RJ45/4CP-G-DIN |
| korenix | jetwave_2212g_firmware | 1.4 |
| korenix | jetwave_2212s_firmware | 1.5 |
…and 12 more
Timeline
- Oct 7, 2020 PoC Published
- Oct 12, 2020 PoC Published
- Oct 15, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 1, 2021 PoC Published
- Aug 23, 2021 EPSS Score
- Oct 24, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 5, 2022 PoC Published
- Feb 25, 2022 EPSS Score
- Apr 28, 2022 EPSS Score
References
- https://cert.vde.com/de-de/advisories/vde-2020-040 url
- 20210601 SEC Consult SA-20210601-0 :: Multiple critical vulnerabilities in Korenix Technology JetNet Series mailing-list
- http://packetstormsecurity.com/files/162903/Korenix-CSRF-Backdoor-Accounts-Command-Injection-Missing-Authentication.html url
- https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs/ url
- https://cert.vde.com/en-us/advisories/vde-2020-053 url
- http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html url
- https://nvd.nist.gov/vuln/detail/CVE-2020-12504 advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-korenix-technology-westermo-pepperl-fuchs url