CVE-2020-12495 - CVE House
Back to Database
Status published Critical CVE-2020-12495

ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege management

Vulnerability Description

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens". The vulnerability is that user sessions are not closed correctly and a user with fewer rights is assigned the higher rights when he logs on.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12495

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Maxim Rupp reported this vulnerability to CERT@VDE

Affected Vendor

Endress+Hauser

View all reports →

Affected Software

RSG35 - Ecograph T, ORSG35 - Ecograph T Neutral/Private Label
Vulnerable Versions:
V1.0.0

Timeline

Official Publish: November 19th, 2020
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)