PT-2020-20262 · Phoenix Contact · Phoenix Contact Emalytics Controller Ilc 2050 Bi+1
Published
2020-02-17
·
Updated
2022-01-01
·
CVE-2020-8768
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Phoenix Contact Emalytics Controller ILC 2050 BI versions prior to 1.2.3
Phoenix Contact Emalytics Controller BI-L versions prior to 1.2.3
Description
An issue was discovered related to an insecure mechanism for read and write access to the device configuration. This mechanism can be discovered by examining a link on the device's website.
Recommendations
For Phoenix Contact Emalytics Controller ILC 2050 BI versions prior to 1.2.3, update to version 1.2.3 or later to resolve the issue.
For Phoenix Contact Emalytics Controller BI-L versions prior to 1.2.3, update to version 1.2.3 or later to resolve the issue.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phoenix Contact Emalytics Controller Bi-L
Phoenix Contact Emalytics Controller Ilc 2050 Bi