Article No° | Product Name | Affected Version(s) |
---|---|---|
194233 | OIT1500-F113-B12-CB | <= V2.11.0 |
194231 | OIT200-F113-B12-CB | <= V2.11.0 |
194232 | OIT500-F113-B12-CB | <= V2.11.0 |
295845 | OIT700-F113-B12-CB | <= V2.11.0 |
Critical vulnerabilities has been discovered in the product, mainly caused by an
anonymous FTP server and Telnet access.
The impact of the vulnerabilities on the affected device may result in
An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.
Pepperl+Fuchs analyzed and identified affected devices.
An attacker can
An external protective measure is required.
CERT@VDE coordinated with Pepperl+Fuchs.
The vulnerabilities were reported by BMW AG.