# CVE-2026-27565

## Summary

- **CVE ID:** CVE-2026-27565
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-78
- **Published:** Sep 16, 2026
- **Last Modified:** Sep 16, 2026

## Description

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

## Affected Products

- Pepperl+Fuchs — ICE2-8IOL1-G65L-V1D (1.0.0)
- Pepperl+Fuchs — ICE2-8IOL-G65L-V1D (1.0.0)
- Pepperl+Fuchs — ICE2-8IOL-K45P-RJ45 (1.0.0)
- Pepperl+Fuchs — ICE2-8IOL-K45S-RJ45 (1.0.0)
- Pepperl+Fuchs — ICE3-8IOL1-G65L-V1D (1.0.0)
- Pepperl+Fuchs — ICE3-8IOL-G65L-V1D (1.0.0)
- Pepperl+Fuchs — ICE3-8IOL-G65L-V1D-Y (1.0.0)
- Pepperl+Fuchs — ICE3-8IOL-K45P-RJ45 (1.0.0)
- Pepperl+Fuchs — ICE3-8IOL-K45S-RJ45 (1.0.0)
- Phoenix Contact — IOL MA8 PN DI8 (1.0.0)
- Phoenix Contact — IOL MA8 EIP DI8 (1.0.0)
- Carlo Gavazzi Automation — YL212CEI8M1IO (1.0.0)
- Carlo Gavazzi Automation — YN115CEI8RPIO (1.0.0)
- Carlo Gavazzi Automation — YL212CPN8M1IO (1.0.0)
- Carlo Gavazzi Automation — YN115CPN8RPIO (1.0.0)

## References

- [CNA](https://www.certvde.com/en/advisories/VDE-2026-014/)
- [CNA](https://www.certvde.com/en/advisories/VDE-2026-027/)
- [CNA](https://www.certvde.com/en/advisories/VDE-2026-028/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.94%
- **EPSS Percentile:** 59.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._