An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanism for read and write access to the configuration of the device. The mechanism can be discovered by examining a link on the website of the device.
2020-02-17T21:15:13.587
2024-11-21T05:39:24.313
Modified
CVSSv3.1: 9.4 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | phoenixcontact | ilc_2050_bi_firmware | < 1.2.3 | Yes |
| Hardware | phoenixcontact | ilc_2050_bi | - | No |
| Operating System | phoenixcontact | ilc_2050_bi-l_firmware | < 1.2.3 | Yes |
| Hardware | phoenixcontact | ilc_2050_bi-l | - | No |