
CVE-2020-12514 – Pepper+Fuchs Comtrol IO-Link Master NULL Pointer Dereference
https://notcve.org/view.php?id=CVE-2020-12514
13 Jan 2021 — Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd Pepperl + Fuchs Comtrol IO-Link Master en la versión 1.5.48 y anteriores, es propenso a una desreferencia del puntero NULL que conduce a una DoS en discoveryd Pepperl+Fuchs IO-Link Master Series with system version 1.36 and application version 1.5.28 suffers from command injection, cross site request forgery, cross site scripting, denial of service, and null pointer vulne... • https://packetstorm.news/files/id/160933 • CWE-476: NULL Pointer Dereference •

CVE-2020-12511 – Pepper+Fuchs Comtrol IO-Link Master Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2020-12511
13 Jan 2021 — Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface. Pepperl + Fuchs Comtrol IO-Link Master en la versión 1.5.48 y anteriores, es propenso a una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en la interfaz web Pepperl+Fuchs IO-Link Master Series with system version 1.36 and application version 1.5.28 suffers from command injection, cross site request forgery, cross site scripting, denial of service, and null pointer... • https://packetstorm.news/files/id/160933 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2020-12512 – Pepper+Fuchs Comtrol IO-Link Master Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2020-12512
13 Jan 2021 — Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting Pepperl + Fuchs Comtrol IO-Link Master en la versión 1.5.48 y anteriores, es propenso a un ataque de tipo Cross-Site Scripting reflejado autenticado de una POST Pepperl+Fuchs IO-Link Master Series with system version 1.36 and application version 1.5.28 suffers from command injection, cross site request forgery, cross site scripting, denial of service, and null pointer vulnerabili... • https://packetstorm.news/files/id/160933 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-12513 – Pepper+Fuchs Comtrol IO-Link Master OS Command Injection
https://notcve.org/view.php?id=CVE-2020-12513
13 Jan 2021 — Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection. Pepperl + Fuchs Comtrol IO-Link Master en la versión 1.5.48 y anteriores, es propenso a una inyección de comandos de Sistema Operativo ciega autenticada Pepperl+Fuchs IO-Link Master Series with system version 1.36 and application version 1.5.28 suffers from command injection, cross site request forgery, cross site scripting, denial of service, and null pointer vulnerabilities. • https://packetstorm.news/files/id/160933 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •