Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-9201


Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.


Published

2019-02-26T23:29:00.357

Last Modified

2024-11-21T04:51:11.683

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

8.5

Weaknesses
  • Type: Primary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System phoenixcontact ilc_131_eth_firmware - Yes
Hardware phoenixcontact ilc_131_eth - No
Operating System phoenixcontact ilc_131_eth\/xc_firmware - Yes
Hardware phoenixcontact ilc_131_eth\/xc - No
Operating System phoenixcontact ilc_151_eth_firmware - Yes
Hardware phoenixcontact ilc_151_eth - No
Operating System phoenixcontact ilc_151_eth\/xc_firmware - Yes
Hardware phoenixcontact ilc_151_eth\/xc - No
Operating System phoenixcontact ilc_171_eth_2tx_firmware - Yes
Hardware phoenixcontact ilc_171_eth_2tx - No
Operating System phoenixcontact ilc_191_eth_2tx_firmware - Yes
Hardware phoenixcontact ilc_191_eth_2tx - No
Operating System phoenixcontact ilc_191_me\/an_firmware - Yes
Hardware phoenixcontact ilc_191_me\/an - No
Operating System phoenixcontact axc_1050_firmware - Yes
Hardware phoenixcontact axc_1050 - No

References