CVE-2016-8380
published 2018-04-05CVE-2016-8380: The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
PriorityP262high7.3CVSS 3.0
AVNACLPRNUINSUCLILAL
EXPLOIT
EPSS
11.20%
95.4th percentile
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | phoenix_contact_ilc_plcs | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated HTTP GET requests to /cgi-bin/ILRReadValues.exe on Phoenix Contact ILC PLC web servers — this endpoint exposes all PLC tag values without authentication. ↗
- →Detect unauthenticated HTTP GET requests to /cgi-bin/writeVal.exe on Phoenix Contact ILC PLC web servers — this endpoint allows writing arbitrary PLC variable values without authentication. ↗
- →Detect HTTP requests fetching *.tcr files from the PLC root — this file enumerates all PLC tag names and is a precursor step in exploitation. ↗
- →Monitor for HTTP requests to the PLC root page (/) that parse the 'ProjectName' VALUE field — this is the reconnaissance step used to discover the project name before fetching the .tcr tag list. ↗
- →The web server allows access to read and write PLC variables without authentication — alert on any access to ILRReadValues.exe or writeVal.exe from untrusted network segments. ↗
- ·The authentication bypass (CVE-2016-8371) means even password-protected HMI pages can be bypassed — do not rely on the WebVisit password macro as a security control. ↗
- ·The WebVisit password macro can be configured to store and transfer passwords in cleartext (CVE-2016-8366) — inspect configurations for plaintext password storage. ↗
- ·All ILC 1xx PLC firmware versions are affected; only ILC 1x1 PLCs with Firmware 4.42 or later offer HTTPS, which partially mitigates exposure. ↗
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Phoenix Contact ILC PLC Authentication Vulnerabilities
cisa_ics·2019-01-24
Phoenix Contact ILC PLC Authentication Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Phoenix Contact ILC PLC Authentication Vulnerabilities
Last RevisedJanuary 24, 2019
Alert CodeICSA-16-313-01
## OVERVIEW
Matthias Niedermaier and Michael Kapfer of HSASec Hochschule Augsburg have identified authentication vulnerabilities in Phoenix Contact’s ILC (inline controller) PLCs. Phoenix Contact GmbH & Co. KG has produced a mitigation plan that includes an update and recommended security practices to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
Phoenix Contact reports that these vulnerabilities affect the foll
GHSA
GHSA-23m3-jp2w-3vpp: The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication
ghsa_unreviewed·2022-05-14
CVE-2016-8380 [HIGH] CWE-287 GHSA-23m3-jp2w-3vpp: The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
No detection rules found.
No writeups or analysis indexed.
2018-04-05
Published