CVE-2026-27553

Summary

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

Affected Software

VendorProductVersion RangeStatus
Pepperl+FuchsICE2-8IOL1-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-K45P-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-K45S-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL1-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-G65L-V1D-Y1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-K45P-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-K45S-RJ451.0.0 < 1.7.4affected
Phoenix ContactIOL MA8 PN DI81.0.0 < 1.7.4affected
Phoenix ContactIOL MA8 EIP DI81.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYL212CEI8M1IO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYN115CEI8RPIO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYL212CPN8M1IO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYN115CPN8RPIO1.0.0 < 1.7.4affected

Weaknesses

  • CWE-497: CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere

References