PT-2020-8612 · Phoenix Contact+1 · Axl F Bk Eth Xc+4
Published
2020-02-18
·
Updated
2020-08-24
·
CVE-2018-16994
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
PHOENIX CONTACT AXL F BK PN versions 1.0.4 and earlier
PHOENIX CONTACT AXL F BK ETH versions 1.12 and earlier
PHOENIX CONTACT AXL F BK ETH XC versions 1.11 and earlier
Bosch Rexroth S20-ETH-BK (affected versions not specified)
Bosch Rexroth S20-PN-BK+ (affected versions not specified)
Description:
The issue allows remote attackers to initiate a complete lock up of the bus coupler due to incorrect handling of a request with non-standard symbols. No authentication of the request is required.
Recommendations:
For PHOENIX CONTACT AXL F BK PN versions 1.0.4 and earlier, update to a version later than 1.0.4.
For PHOENIX CONTACT AXL F BK ETH versions 1.12 and earlier, update to a version later than 1.12.
For PHOENIX CONTACT AXL F BK ETH XC versions 1.11 and earlier, update to a version later than 1.11.
For Bosch Rexroth S20-ETH-BK and S20-PN-BK+, contact the vendor for specific guidance on updating or mitigating the issue.
As a temporary workaround, consider restricting access to the bus coupler to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Axl F Bk Eth
Axl F Bk Eth Xc
Axl F Bk Pn
S20-Eth-Bk
S20-Pn-Bk+