PT-2019-14760 · Phoenix Contact · Pc Worx+2

Published

2019-10-29

·

Updated

2020-08-24

·

CVE-2019-16675

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHOENIX CONTACT PC Worx versions 1.86 and earlier PHOENIX CONTACT PC Worx Express versions 1.86 and earlier PHOENIX CONTACT Config+ versions 1.86 and earlier
Description An issue was discovered that could lead to an Out-of-bounds Read and remote code execution. This occurs when a manipulated project file is used, which can happen if an attacker gains access to an original project file, manipulates the data, and then exchanges the original file with the manipulated one on the application programming workstation.
Recommendations For PHOENIX CONTACT PC Worx versions 1.86 and earlier, consider restricting access to project files to prevent manipulation. For PHOENIX CONTACT PC Worx Express versions 1.86 and earlier, avoid using potentially manipulated project files until a fix is available. For PHOENIX CONTACT Config+ versions 1.86 and earlier, as a temporary workaround, consider validating all project files before use to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16675
ZDI-19-922
ZDI-19-923
ZDI-19-991

Affected Products

Config+
Pc Worx
Pc Worx Express