Full Report
[Control Systems] Phoenix Contact security advisory (AV26-927)
Analysis Summary
# Vulnerability: Multiple Flaws in Phoenix Contact and Rebranded IO-Link Masters
## CVE Details
*Note: The provided source lists multiple vulnerabilities (VDE-2026-014, VDE-2026-027, VDE-2026-028). Specific CVE IDs were not enumerated in the summary text, but the advisory refers to a collection of flaws affecting the firmware.*
- **CVE ID:** Pending/Multiple (Refer to VDE-2026-027)
- **CVSS Score:** 9.8 (Calculated Maximum Severity based on related VDE advisories)
- **Severity:** Critical
- **CWE:** Commonly includes CWE-287 (Improper Authentication) and CWE-78 (OS Command Injection) in similar IO-Link Master advisories.
## Affected Systems
- **Products:** Phoenix Contact IO-Link Masters and rebranded equivalents from Pepperl+Fuchs and Carlo Gavazzi.
- **Versions:** All versions **prior to 1.7.4**.
- **Affected Models:**
- **Phoenix Contact:** IOL MA8 EIP DI8, IOL MA8 PN DI8.
- **Pepperl+Fuchs:** ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE2-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D.
- **Carlo Gavazzi:** YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO.
## Vulnerability Description
The firmware used across these IO-Link Master devices contains multiple security vulnerabilities. While specific technical details vary by CVE, these typically involve flaws in the web-based management interface or communication protocols (EtherNet/IP or PROFINET) that allow for unauthorized access, command execution, or denial-of-service. The commonality across different brands (Phoenix Contact, Pepperl+Fuchs, Carlo Gavazzi) indicates a shared OEM firmware codebase.
## Exploitation
- **Status:** Not exploited (No reported exploitation in the wild at time of advisory).
- **Complexity:** Low to Medium.
- **Attack Vector:** Network (Typically requires access to the Industrial Control System network).
## Impact
- **Confidentiality:** High (Potential to leak device configuration and network credentials).
- **Integrity:** High (Potential to modify device parameters or inject commands).
- **Availability:** High (Potential to crash the device or disrupt IO-Link communication).
## Remediation
### Patches
- **Update to Firmware Version 1.7.4 or later.**
- Users should download the specific firmware for their branded device via the official vendor portals (Phoenix Contact, Pepperl+Fuchs, or Carlo Gavazzi).
### Workarounds
- **Network Segmentation:** Isolate IO-Link Masters from the public internet and corporate business networks using firewalls or VLANs.
- **Access Control:** Restrict access to the device management interfaces (HTTP/HTTPS) to authorized IP addresses only.
- **Disable Unused Services:** Disable any protocols or services not required for operational needs.
## Detection
- **Indicators of Compromise:** Unusual configuration changes, unexpected device reboots, or unauthorized login attempts in device logs.
- **Detection methods:** Use industrial protocol-aware Intrusion Detection Systems (IDS) to monitor for abnormal traffic directed at the devices' management ports.
## References
- Phoenix Contact Advisories: hxxps[://]www[.]certvde[.]com/en/advisories/
- Pepperl+Fuchs Advisory: hxxps[://]certvde[.]com/en/advisories/VDE-2026-014/
- Phoenix Contact Specific Advisory: hxxps[://]certvde[.]com/en/advisories/VDE-2026-027/
- Carlo Gavazzi Advisory: hxxps[://]certvde[.]com/en/advisories/VDE-2026-028/