pepperl-fuchs CVE Vulnerabilities & Metrics

Focus on pepperl-fuchs vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About pepperl-fuchs Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with pepperl-fuchs. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total pepperl-fuchs CVEs: 21
Earliest CVE date: 04 Jan 2018, 13:29 UTC
Latest CVE date: 31 Aug 2021, 11:15 UTC

Latest CVE reference: CVE-2021-34565

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical pepperl-fuchs CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.55

Max CVSS: 9.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 11
7.0-8.9 5
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS pepperl-fuchs CVEs

These are the five CVEs with the highest CVSS scores for pepperl-fuchs, sorted by severity first and recency.

All CVEs for pepperl-fuchs

CVE-2021-34565 pepperl-fuchs vulnerability CVSS: 7.5 31 Aug 2021, 11:15 UTC

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

CVE-2021-34564 pepperl-fuchs vulnerability CVSS: 2.1 31 Aug 2021, 11:15 UTC

Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.

CVE-2021-34563 pepperl-fuchs vulnerability CVSS: 2.1 31 Aug 2021, 11:15 UTC

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.

CVE-2021-34562 pepperl-fuchs vulnerability CVSS: 4.3 31 Aug 2021, 11:15 UTC

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.

CVE-2021-34561 pepperl-fuchs vulnerability CVSS: 6.8 31 Aug 2021, 11:15 UTC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.

CVE-2021-34560 pepperl-fuchs vulnerability CVSS: 2.1 31 Aug 2021, 11:15 UTC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.

CVE-2021-34559 pepperl-fuchs vulnerability CVSS: 5.0 31 Aug 2021, 11:15 UTC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.

CVE-2021-33555 pepperl-fuchs vulnerability CVSS: 5.0 31 Aug 2021, 11:15 UTC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.

CVE-2021-20988 pepperl-fuchs vulnerability CVSS: 5.0 13 May 2021, 14:15 UTC

In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.

CVE-2021-20987 pepperl-fuchs vulnerability CVSS: 7.8 16 Feb 2021, 17:15 UTC

A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.

CVE-2021-20986 pepperl-fuchs vulnerability CVSS: 5.0 16 Feb 2021, 17:15 UTC

A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.

CVE-2020-12514 pepperl-fuchs vulnerability CVSS: 4.0 22 Jan 2021, 19:15 UTC

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd

CVE-2020-12513 pepperl-fuchs vulnerability CVSS: 9.0 22 Jan 2021, 19:15 UTC

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.

CVE-2020-12512 pepperl-fuchs vulnerability CVSS: 3.5 22 Jan 2021, 19:15 UTC

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting

CVE-2020-12511 pepperl-fuchs vulnerability CVSS: 6.8 22 Jan 2021, 19:15 UTC

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.

CVE-2020-12504 pepperl-fuchs vulnerability CVSS: 7.5 15 Oct 2020, 19:15 UTC

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

CVE-2020-12503 pepperl-fuchs vulnerability CVSS: 6.5 15 Oct 2020, 19:15 UTC

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.

CVE-2020-12502 pepperl-fuchs vulnerability CVSS: 6.8 15 Oct 2020, 19:15 UTC

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.

CVE-2020-12501 pepperl-fuchs vulnerability CVSS: 7.5 15 Oct 2020, 19:15 UTC

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

CVE-2020-12500 pepperl-fuchs vulnerability CVSS: 7.5 15 Oct 2020, 19:15 UTC

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.

CVE-2017-5753 pepperl-fuchs vulnerability CVSS: 4.7 04 Jan 2018, 13:29 UTC

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.