Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial controller devices are vulnerable to unauthenticated remote code execution through malicious IODD (IO Device Description) file uploads. An attacker can execute arbitrary shell commands with root privileges that persist across device reboots, giving complete control over critical factory automation equipment and potentially affecting downstream production systems.
Technical details
The vulnerability is an OS command injection (CWE-78) in the IODD file processing logic that fails to properly sanitize user-supplied input. An unauthenticated remote attacker can upload a specially crafted IODD file that embeds shell commands, which are then executed with root-level privileges on the device. The injected shell script persists in the device's filesystem and continues to execute even after reboot, establishing a persistent foothold. No authentication or user interaction is required; the attack is network-accessible and has low attack complexity.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4
Timeline
- 2026-09-16: disclosed