Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial IO link master devices use an authentication system to control access to sensitive device functions. An authenticated operator with low privileges can exploit a command injection flaw in the Field_Shadow_Password class to execute arbitrary commands with root-level access, allowing complete compromise of the device's integrity and control.
Technical details
The vulnerability is an OS command injection (CWE-78) in the Field_Shadow_Password class that fails to properly sanitize user input before passing it to system commands. An attacker with valid operator credentials can inject shell metacharacters into the vulnerable code path to execute arbitrary commands with root privileges on the device. The attack requires network access and valid low-privileged credentials, but no additional user interaction. Successful exploitation allows root-level code execution, enabling device takeover, data exfiltration, or persistent backdoors. Firmware version 1.7.4 and later patch this vulnerability across affected ICE2-* and ICE3-* models.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D < 1.7.4
- Phoenix Contact IOL MA8 EIP DI8 < 1.7.4
- Phoenix Contact IOL MA8 PN DI8 < 1.7.4
Timeline
- 2026-09-16: disclosed: Vulnerability published and advisory released