CVE-2020-12519
published 2020-12-17CVE-2020-12519: On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.85%
54.1th percentile
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | axc_f_1152 | >= unspecified < 2021.0 LTS | 2021.0 LTS |
| phoenix_contact | axc_f_2152 | >= unspecified < 2021.0 LTS | 2021.0 LTS |
| phoenix_contact | axc_f_2152_starterkit | >= unspecified < 2021.0 LTS | 2021.0 LTS |
| phoenix_contact | axc_f_3152 | >= unspecified < 2021.0 LTS | 2021.0 LTS |
| phoenix_contact | plcnext_technology_starterkit | >= unspecified < 2021.0 LTS | 2021.0 LTS |
| phoenix_contact | rfc_4072s_1051328 | >= unspecified < 2021.0 LTS | 2021.0 LTS |
| phoenixcontact | plcnext_firmware | < 2021.0 | 2021.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS ShopNx - Arbitrary File Upload
suricata·2018-07-05
CVE-2018-12519 ET WEB_SPECIFIC_APPS ShopNx - Arbitrary File Upload
ET WEB_SPECIFIC_APPS ShopNx - Arbitrary File Upload
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ShopNx - Arbitrary File Upload"; flow:established,to_server; http.uri; content:"/api/media"; fast_pattern; endswith; http.request_body; content:"<script"; reference:cve,2018-12519; reference:url,exploit-db.com/exploits/44978/; classtype:web-application-attack; sid:2025784; rev:3; metadata:attack_target Web_Server, created_at 2018_07_05, cve CVE_2018_12519, deployment Datacenter, performance_impact Low, signature_severity Major, updated_at 2020_09_16;)
No public exploits indexed.
No writeups or analysis indexed.
2020-12-17
Published