Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10997


An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually via a Linux shell.


Published

2019-06-17T18:15:10.703

Last Modified

2024-11-21T04:20:19.233

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

6.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System phoenixcontact axc_f_2152_firmware < 2019.0_lts Yes
Hardware phoenixcontact axc_f_2152 - No
Operating System phoenixcontact axc_f_2152_starterkit_firmware < 2019.0_lts Yes
Hardware phoenixcontact axc_f_2152_starterkit - No

References