Junglewise Threat Intelligence

CVE-2026-27565: Pepperl+Fuchs ICE2/ICE3 OS command injection in IODD file upload

CVE-2026-27565 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Technologies: Pepperl+Fuchs ICE2-8IOL-K45P-RJ45, Pepperl+Fuchs ICE2-8IOL1-G65L-V1D, Pepperl+Fuchs ICE2-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, Pepperl+Fuchs ICE2-8IOL-K45S-RJ45, Pepperl+Fuchs ICE3-8IOL1-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45P-RJ45, Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y, Pepperl+Fuchs ICE3-8IOL-G65L-V1D. Vendors: Pepperl+Fuchs.

Executive brief

Pepperl+Fuchs ICE2 and ICE3 industrial controller devices are vulnerable to unauthenticated remote code execution through malicious IODD (IO Device Description) file uploads. An attacker can execute arbitrary shell commands with root privileges that persist across device reboots, giving complete control over critical factory automation equipment and potentially affecting downstream production systems.

Technical details

The vulnerability is an OS command injection (CWE-78) in the IODD file processing logic that fails to properly sanitize user-supplied input. An unauthenticated remote attacker can upload a specially crafted IODD file that embeds shell commands, which are then executed with root-level privileges on the device. The injected shell script persists in the device's filesystem and continues to execute even after reboot, establishing a persistent foothold. No authentication or user interaction is required; the attack is network-accessible and has low attack complexity.

Affected products

  • Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
  • Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
  • Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4

Timeline

  • 2026-09-16: disclosed

References

Related threats