PT-2019-6215 · Phoenix Contact · Rfc 480S Pn 4Tx+14
Sergiu Sechel
·
Published
2019-02-26
·
Updated
2024-02-14
·
CVE-2019-9201
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ILC 1x0 versions (affected versions not specified)
ILC 1x1 versions (affected versions not specified)
ILC 1x1 GSM/GPRS versions (affected versions not specified)
ILC 3xx versions (affected versions not specified)
AXC 1050 versions (affected versions not specified)
AXC 1050 XC versions (affected versions not specified)
AXC 3050 versions (affected versions not specified)
RFC 480S PN 4TX versions (affected versions not specified)
RFC 470 PN 3TX versions (affected versions not specified)
RFC 470S PN 3TX versions (affected versions not specified)
RFC 460R PN 3TX versions (affected versions not specified)
RFC 460R PN 3TX-S versions (affected versions not specified)
RFC 430 ETH-IB versions (affected versions not specified)
RFC 450 ETH-IB versions (affected versions not specified)
PC WORX SRT versions (affected versions not specified)
PC WORX RT BASIC versions (affected versions not specified)
FC 350 PCI ETH versions (affected versions not specified)
Description
The issue is related to weaknesses in the authentication procedure of the software. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information or impact the integrity of the information by establishing a TCP session on port 1962. This can be demonstrated by using the Create Backup feature to traverse all directories.
Recommendations
As a temporary workaround, consider restricting access to port 1962 to minimize the risk of exploitation.
Avoid using the Create Backup feature until the issue is resolved.
Restrict access to sensitive information and directories to prevent unauthorized access.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Axc 1050
Axc 1050 Xc
Axc 3050
Fc 350 Pci Eth
Ilc1X0
Ilc1X1
Ilc 1X1 Gsm/Gprs
Ilc 3Xx
Pc Worx Rt Basic
Pc Worx Srt
Rfc 430 Eth-Ib
Rfc 450 Eth-Ib
Rfc 460R Pn 3Tx
Rfc 470S Pn 3Tx
Rfc 480S Pn 4Tx