Zurück zur Übersicht

Pepperl+Fuchs: Multiple Products - Vulnerability may allow remote attackers to cause a Denial Of Service

VDE-2020-050
Last update
14.05.2025 15:00
Published at
15.02.2021 14:33
Vendor(s)
Pepperl+Fuchs SE
External ID
VDE-2020-050
CSAF Document

Summary

Critical vulnerability has been discovered in the utilized component 499ES EtherNet/IP Stack by Real Time Automation (RTA).

Impact

Pepperl+Fuchs analyzed and identified affected devices.
Remote attackers may exploit the vulnerability sending specially crafted packages that may result in a denial-of-service condition or code execution.

Affected Product(s)

Model no. Product name Affected versions
IC-KP-B17-AIDA1 Firmware <=18-31785F
IC-KP2-1HB17-2V1D Firmware <=18-31766H
IC-KP2-2HB17-2V1D Firmware <=18-31440H

Vulnerabilities

Expand / Collapse all

Published
02.09.2026 14:29
Weakness
Stack-based Buffer Overflow (CWE-121)
Summary

499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker to send a specially crafted packet that may result in a denial-of-service condition or code execution.

References

Mitigation

An external protective measure is required.

  • Minimize network exposure for affected products and ensure that they are not accessible via the Internet.
  • Isolate affected products from the corporate network.
  • If remote access is required, use secure methods such as virtual private networks (VPNs).

Acknowledgments

Pepperl+Fuchs SE thanks the following parties for their efforts:

  • CERT@VDE for coordination (see https://certvde.com )
  • Sharon Brizinov from Claroty for reporting this vulnerability

Revision History

Version Date Summary
1 15.02.2021 14:33 Initial revision.
2 10.04.2025 15:00 Fixed URLs.
3 14.05.2025 15:00 Fix: added distribution