CVE-2020-9436
published 2020-03-12CVE-2020-9436: PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.61%
83.6th percentile
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated users to inject system commands through a modified POST request to a specific URL.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenixcontact | tc_cloud_client_1002-4g_firmware | <= 2.03.17 | — |
| phoenixcontact | tc_cloud_client_1002-txtx_firmware | <= 1.03.17 | — |
| phoenixcontact | tc_router_2002t-3g_firmware | <= 2.05.3 | — |
| phoenixcontact | tc_router_3002t-4g_att_firmware | <= 2.05.3 | — |
| phoenixcontact | tc_router_3002t-4g_firmware | <= 2.05.3 | — |
| phoenixcontact | tc_router_3002t-4g_vzw_firmware | <= 2.05.3 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/156729/Phoenix-Contact-TC-Router-TC-Cloud-Client-Command-Injection.htmlhttp://seclists.org/fulldisclosure/2020/Mar/15https://cert.vde.com/en-us/advisories/https://cert.vde.com/en-us/advisories/vde-2020-003http://packetstormsecurity.com/files/156729/Phoenix-Contact-TC-Router-TC-Cloud-Client-Command-Injection.htmlhttp://seclists.org/fulldisclosure/2020/Mar/15https://cert.vde.com/en-us/advisories/https://cert.vde.com/en-us/advisories/vde-2020-003
2020-03-12
Published