Vulnerabilities > Pepperl Fuchs > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-38502 Cross-site Scripting vulnerability in Pepperl-Fuchs products
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
network
low complexity
pepperl-fuchs CWE-79
7.1
2024-08-13 CVE-2024-5849 Cross-site Scripting vulnerability in Pepperl-Fuchs products
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
network
low complexity
pepperl-fuchs CWE-79
7.1
2021-08-31 CVE-2021-33555 Unspecified vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.
network
low complexity
pepperl-fuchs
7.5
2021-08-31 CVE-2021-34561 Unspecified vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions.
network
low complexity
pepperl-fuchs
8.8
2021-05-13 CVE-2021-20988 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet.
network
low complexity
hilscher pepperl-fuchs CWE-119
7.5
2021-02-16 CVE-2021-20987 Out-of-bounds Write vulnerability in multiple products
A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.
network
low complexity
hilscher pepperl-fuchs CWE-787
8.6
2021-02-16 CVE-2021-20986 Out-of-bounds Write vulnerability in multiple products
A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7.
network
low complexity
hilscher pepperl-fuchs CWE-787
7.5
2021-01-22 CVE-2020-12525 Deserialization of Untrusted Data vulnerability in multiple products
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
7.8
2021-01-22 CVE-2020-12513 OS Command Injection vulnerability in Pepperl-Fuchs products
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
network
low complexity
pepperl-fuchs CWE-78
8.8
2021-01-22 CVE-2020-12511 Cross-Site Request Forgery (CSRF) vulnerability in Pepperl-Fuchs products
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.
network
low complexity
pepperl-fuchs CWE-352
8.8