← All Advisories

Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-27557

Key Details

CVECVE-2026-27557
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-16
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productssee table below
Classified asCWE-35 (Path Traversal: '.../...//')

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Pepperl+FuchsICE2-8IOL-K45P-RJ45
Pepperl+FuchsICE2-8IOL1-G65L-V1D
Pepperl+FuchsICE2-8IOL-G65L-V1D
Pepperl+FuchsICE2-8IOL-K45S-RJ45
Pepperl+FuchsICE3-8IOL1-G65L-V1D
Pepperl+FuchsICE3-8IOL-G65L-V1D
Pepperl+FuchsICE3-8IOL-G65L-V1D-Y
Pepperl+FuchsICE3-8IOL-K45P-RJ45
Pepperl+FuchsICE3-8IOL-K45S-RJ45
Phoenix ContactIOL MA8 PN DI8
Phoenix ContactIOL MA8 EIP DI8
Carlo Gavazzi AutomationYL212CEI8M1IO
Carlo Gavazzi AutomationYN115CEI8RPIO
Carlo Gavazzi AutomationYL212CPN8M1IO
Carlo Gavazzi AutomationYN115CPN8RPIO
SubsystemsGeneral OT
SectorsMultiple

What to Know

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

What to Do

Monitor Pepperl+Fuchs, Phoenix Contact, and Carlo Gavazzi Automation's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-27557
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-27557