PT-2021-20189 · Phoenix Contact · Phoenix Contact Automation Worx Software Suite
Francis Provencher
·
Published
2021-06-25
·
Updated
2021-09-20
·
CVE-2021-33542
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Phoenix Contact Classic Automation Worx Software Suite versions 1.87 and below
Description
The issue concerns a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to remote code execution when unallocated memory is freed due to incompletely initialized data. An attacker needs access to an original bus configuration file (
*.bcp) to manipulate data inside. After manipulation, the attacker must exchange the original file with the manipulated one on the application programming workstation. This could compromise the availability, integrity, or confidentiality of an application programming workstation. Automated systems in operation programmed with the mentioned products are not affected.Recommendations
For Phoenix Contact Classic Automation Worx Software Suite versions 1.87 and below, consider restricting access to the
*.bcp files to minimize the risk of exploitation. As a temporary workaround, limit the ability to exchange original files with manipulated ones on the application programming workstation until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Access of Uninitialized Pointer
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phoenix Contact Automation Worx Software Suite