PT-2020-5910 · Phoenix Contact · Pc Worx Express+1

Natnael Samson

+1

·

Published

2020-07-01

·

Updated

2023-01-28

·

CVE-2020-12497

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier
Description: The issue is related to the parsing of PLCopen XML files in Phoenix Contact PC Worx and PC Worx Express, which can lead to a stack-based overflow due to insufficient input data validation. This can result in remote code execution if manipulated PC Worx projects are used. The vulnerability is associated with a buffer overflow, allowing an attacker to execute arbitrary code.
Recommendations: For versions 1.87 and earlier, update to a version later than 1.87 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2021-02006
CVE-2020-12497
ZDI-20-825
ZDI-21-398

Affected Products

Pc Worx
Pc Worx Express