Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-12518


On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.


Published

2020-12-17T23:15:12.983

Last Modified

2024-11-21T04:59:51.163

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System phoenixcontact plcnext_firmware < 2021.0 Yes
Hardware phoenixcontact axc_f_1152 - No
Operating System phoenixcontact plcnext_firmware < 2021.0 Yes
Hardware phoenixcontact axc_f_2152 - No
Operating System phoenixcontact plcnext_firmware < 2021.0 Yes
Hardware phoenixcontact axc_f_3152 - No
Operating System phoenixcontact plcnext_firmware < 2021.0 Yes
Hardware phoenixcontact rfc_4072s - No
Operating System phoenixcontact plcnext_firmware < 2021.0 Yes
Hardware phoenixcontact axc_f_2152_starterkit - No
Operating System phoenixcontact plcnext_firmware < 2021.0 Yes
Hardware phoenixcontact plcnext_technology_starterkit - No

References