VDE-2020-050
Last update
14.05.2025 15:00
Published at
15.02.2021 14:33
Vendor(s)
Pepperl+Fuchs SE
External ID
VDE-2020-050
CSAF Document
Summary
Critical vulnerability has been discovered in the utilized component 499ES EtherNet/IP Stack by Real Time Automation (RTA).
Impact
Pepperl+Fuchs analyzed and identified affected devices.
Remote attackers may exploit the vulnerability sending specially crafted packages that may result in a denial-of-service condition or code execution.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| IC-KP-B17-AIDA1 | Firmware <=18-31785F | |
| IC-KP2-1HB17-2V1D | Firmware <=18-31766H | |
| IC-KP2-2HB17-2V1D | Firmware <=18-31440H |
Vulnerabilities
Expand / Collapse all
Published
02.09.2026 14:29
Severity
Weakness
Stack-based Buffer Overflow (CWE-121)
Summary
499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker to send a specially crafted packet that may result in a denial-of-service condition or code execution.
References
Mitigation
An external protective measure is required.
- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.
- Isolate affected products from the corporate network.
- If remote access is required, use secure methods such as virtual private networks (VPNs).
Acknowledgments
Pepperl+Fuchs SE thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
- Sharon Brizinov from Claroty for reporting this vulnerability
Revision History
| Version | Date | Summary |
|---|---|---|
| 1 | 15.02.2021 14:33 | Initial revision. |
| 2 | 10.04.2025 15:00 | Fixed URLs. |
| 3 | 14.05.2025 15:00 | Fix: added distribution |