PT-2020-8612 · Phoenix Contact+1 · Axl F Bk Eth Xc+4

Published

2020-02-18

·

Updated

2020-08-24

·

CVE-2018-16994

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: PHOENIX CONTACT AXL F BK PN versions 1.0.4 and earlier PHOENIX CONTACT AXL F BK ETH versions 1.12 and earlier PHOENIX CONTACT AXL F BK ETH XC versions 1.11 and earlier Bosch Rexroth S20-ETH-BK (affected versions not specified) Bosch Rexroth S20-PN-BK+ (affected versions not specified)
Description: The issue allows remote attackers to initiate a complete lock up of the bus coupler due to incorrect handling of a request with non-standard symbols. No authentication of the request is required.
Recommendations: For PHOENIX CONTACT AXL F BK PN versions 1.0.4 and earlier, update to a version later than 1.0.4. For PHOENIX CONTACT AXL F BK ETH versions 1.12 and earlier, update to a version later than 1.12. For PHOENIX CONTACT AXL F BK ETH XC versions 1.11 and earlier, update to a version later than 1.11. For Bosch Rexroth S20-ETH-BK and S20-PN-BK+, contact the vendor for specific guidance on updating or mitigating the issue. As a temporary workaround, consider restricting access to the bus coupler to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-16994

Affected Products

Axl F Bk Eth
Axl F Bk Eth Xc
Axl F Bk Pn
S20-Eth-Bk
S20-Pn-Bk+