Executive brief
Industrial ethernet coupling controllers (ICE2 and ICE3 series) used in manufacturing and automation systems contain a path traversal vulnerability in their web diagnostics interface. An authenticated attacker can manipulate file paths to read sensitive password hashes and other credentials stored on the device, potentially leading to account compromise and unauthorized system access.
Technical details
A path traversal vulnerability exists in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint of the ICE2 and ICE3 device firmware. The vulnerability allows a low-privileged attacker with valid user credentials (via cookie) to manipulate the schema path parameter to traverse the filesystem and read arbitrary files. This enables disclosure of password hashes and other sensitive configuration files. The vulnerability requires valid authentication credentials but can be exploited with standard user-level access. Patches are available in firmware version 1.7.4 and later.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4
Timeline
- 2026-09-16: disclosed