CVE-2026-27565

Summary

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

Affected Software

VendorProductVersion RangeStatus
Pepperl+FuchsICE2-8IOL1-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-K45P-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-K45S-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL1-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-G65L-V1D-Y1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-K45P-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-K45S-RJ451.0.0 < 1.7.4affected
Phoenix ContactIOL MA8 PN DI81.0.0 < 1.7.4affected
Phoenix ContactIOL MA8 EIP DI81.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYL212CEI8M1IO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYN115CEI8RPIO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYL212CPN8M1IO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYN115CPN8RPIO1.0.0 < 1.7.4affected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References