CVE-2019-10997
published 2019-06-17CVE-2019-10997: An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol…
PriorityP427medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.00%
58.8th percentile
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually via a Linux shell.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenixcontact | axc_f_2152_firmware | < 2019.0_lts | 2019.0_lts |
| phoenixcontact | axc_f_2152_starterkit_firmware | < 2019.0_lts | 2019.0_lts |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-644p-jwhv-rxr7: An issue was discovered on Phoenix Contact AXC F 2152 (No
ghsa_unreviewed·2022-05-24
CVE-2019-10997 [HIGH] GHSA-644p-jwhv-rxr7: An issue was discovered on Phoenix Contact AXC F 2152 (No
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually via a Linux shell.
CISA ICS
PHOENIX CONTACT PLCNext AXC F 2152
cisa_ics·2019-06-04·CVSS 5.3
[MEDIUM] PHOENIX CONTACT PLCNext AXC F 2152
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
PHOENIX CONTACT PLCNext AXC F 2152
Last RevisedJune 04, 2019
Alert CodeICSA-19-155-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 7.6
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Phoenix Contact
- Equipment: PLCNext AXC F 2152
- Vulnerabilities: Key Management Errors, Improper Access Control, Man-in-the-Middle, Using Component with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to decrypt passwords, bypass authentication, and deny service to the device. In addition, these vulnerabilities
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-17
Published