Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-27565: Pepperl+Fuchs I/O devices let attackers run code as admin
CVE-2026-27565 · published 1 day ago
Summary
The listed Pepperl+Fuchs ICE2 and ICE3 I/O devices can be tricked into accepting a specially crafted IODD file. That file installs a program that runs with full system privileges and stays active even after the device is rebooted. Apply the vendor’s patches, restrict who can upload files, and review device configurations to block unauthenticated access.
What to do
- Update pepperl+fuchs ice2-8iol1-g65l-v1d to version 1.7.4 or later.
- Update pepperl+fuchs ice2-8iol-g65l-v1d to version 1.7.4 or later.
- Update pepperl+fuchs ice2-8iol-k45p-rj45 to version 1.7.4 or later.
- Update pepperl+fuchs ice2-8iol-k45s-rj45 to version 1.7.4 or later.
- Update pepperl+fuchs ice3-8iol1-g65l-v1d to version 1.7.4 or later.
- Update pepperl+fuchs ice3-8iol-g65l-v1d to version 1.7.4 or later.
- Update pepperl+fuchs ice3-8iol-g65l-v1d-y to version 1.7.4 or later.
- Update pepperl+fuchs ice3-8iol-k45p-rj45 to version 1.7.4 or later.
- Update pepperl+fuchs ice3-8iol-k45s-rj45 to version 1.7.4 or later.
- Update phoenix contact iol ma8 pn di8 to version 1.7.4 or later.
- Update phoenix contact iol ma8 eip di8 to version 1.7.4 or later.
- Update carlo gavazzi automation yl212cei8m1io to version 1.7.4 or later.
- Update carlo gavazzi automation yn115cei8rpio to version 1.7.4 or later.
- Update carlo gavazzi automation yl212cpn8m1io to version 1.7.4 or later.
- Update carlo gavazzi automation yn115cpn8rpio to version 1.7.4 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| pepperl+fuchs | ice2-8iol1-g65l-v1d | < 1.7.4 |
| pepperl+fuchs | ice2-8iol-g65l-v1d | < 1.7.4 |
| pepperl+fuchs | ice2-8iol-k45p-rj45 | < 1.7.4 |
| pepperl+fuchs | ice2-8iol-k45s-rj45 | < 1.7.4 |
| pepperl+fuchs | ice3-8iol1-g65l-v1d | < 1.7.4 |
| pepperl+fuchs | ice3-8iol-g65l-v1d | < 1.7.4 |
| pepperl+fuchs | ice3-8iol-g65l-v1d-y | < 1.7.4 |
| pepperl+fuchs | ice3-8iol-k45p-rj45 | < 1.7.4 |
| pepperl+fuchs | ice3-8iol-k45s-rj45 | < 1.7.4 |
| phoenix contact | iol ma8 pn di8 | < 1.7.4 |
| phoenix contact | iol ma8 eip di8 | < 1.7.4 |
| carlo gavazzi automation | yl212cei8m1io | < 1.7.4 |
| carlo gavazzi automation | yn115cei8rpio | < 1.7.4 |
| carlo gavazzi automation | yl212cpn8m1io | < 1.7.4 |
| carlo gavazzi automation | yn115cpn8rpio | < 1.7.4 |
Original advisory text
Remote code execution via uploading a malicious IODD file
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published16 Sep 2026
Updated17 Sep 2026
First seen16 Sep 2026
Track software like this
Free during beta