CVE-2024-38502: Pepperl-Fuchs Eip/modbus Firmware

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

Affected products

  • Pepperl-Fuchs Eip/modbus Firmware: before 1.08 (fixed in 1.08)
  • Pepperl-Fuchs Ethernet/ip Firmware: before 7.22 (fixed in 7.22)
  • Pepperl-Fuchs Icdm-Rx/tcp Socketserver Firmware: before 11.65 (fixed in 11.65)
  • Pepperl-Fuchs Modbus Router Firmware: before 7.09 (fixed in 7.09)
  • Pepperl-Fuchs Modbus Server Firmware: before 7.11 (fixed in 7.11)
  • Pepperl-Fuchs Modbus TCP Firmware: before 7.11 (fixed in 7.11)
  • Pepperl-Fuchs Profinet/modbus Firmware: before 1.0.7 (fixed in 1.0.7)
  • Pepperl-Fuchs Profinet Firmware: before 3.4.9 (fixed in 3.4.9)

Published 2024-08-13. Last modified 2026-06-17.