Back to Database
Status published
High
CVE-2020-12513
Pepper+Fuchs Comtrol IO-Link Master OS Command Injection
Vulnerability Description
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12513
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- T.Weber (SEC Consult Vulnerability Lab) reported this vulnerability. Coordinated by CERT@VDE.
Affected Vendor
Pepper+Fuchs
View all reports →Affected Software
Comtrol IO-Link Master
Vulnerable Versions:
unspecified
Timeline
Official Publish:
January 22nd, 2021
Last Modified:
September 16th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H