Pepperl+Fuchs Profinet Gateway LB8122A.1.EL Unauthenticated Remote Reboot Vulnerability
Vulnerability
A vulnerability exists in the Pepperl+Fuchs Profinet Gateway LB8122A.1.EL, allowing an unauthenticated remote attacker to reboot the device. This issue arises from the device's SNMP protocol, which can be exploited to send read commands that trigger a reboot. Additionally, the vulnerability could be combined with a cross-site scripting (XSS) issue, where an attacker injects a malicious HTML link into the HART transmitter's message field. When accessed, this link could redirect a user to a manipulated website, potentially leading to further exploitation.
Impact
Exploitation of this vulnerability causes the device to reboot, disrupting any ongoing processes or operations.
Remediation
Users are advised to update to the firmware version 1.3.13, which addresses this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
