CVE-2019-16675
published 2019-10-31CVE-2019-16675: An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.31%
87.1th percentile
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenixcontact | config | <= 1.86 | — |
| phoenixcontact | pc_worx | <= 1.86 | — |
| phoenixcontact | pc_worx_express | <= 1.86 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
PHOENIX CONTACT Automation Worx Software Suite
cisa_ics·2019-10-29·CVSS 7.8
[HIGH] PHOENIX CONTACT Automation Worx Software Suite
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
PHOENIX CONTACT Automation Worx Software Suite
Last RevisedOctober 29, 2019
Alert CodeICSA-19-302-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low skill level to exploit
- Vendor: Phoenix Contact
- Equipment: Automation Worx Software Suite
- Vulnerability: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could compromise the availability, integrity, or confidentiality of an application programming workstation. Automated systems programmed using one of the affected products are not impacted.
## 3. TECHNICAL DETAILS
##
GHSA
GHSA-5f64-wpvq-45hw: An issue was discovered in PHOENIX CONTACT PC Worx through 1
ghsa_unreviewed·2022-05-24
CVE-2019-16675 [MEDIUM] GHSA-5f64-wpvq-45hw: An issue was discovered in PHOENIX CONTACT PC Worx through 1
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert.vde.com/en-us/advisorieshttps://www.us-cert.gov/ics/advisories/icsa-19-302-01https://www.zerodayinitiative.com/advisories/ZDI-19-922/https://www.zerodayinitiative.com/advisories/ZDI-19-991/https://cert.vde.com/en-us/advisorieshttps://www.us-cert.gov/ics/advisories/icsa-19-302-01https://www.zerodayinitiative.com/advisories/ZDI-19-922/https://www.zerodayinitiative.com/advisories/ZDI-19-991/
2019-10-31
Published