cbcvebase.
CVE-2022-31800
published 2022-06-21

CVE-2022-31800: An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.46%
70.5th percentile
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

Affected

17 ranges
VendorProductVersion rangeFixed in
phoenix_contactaxc_1050
phoenix_contactaxc_1050_xc
phoenix_contactaxc_3050
phoenix_contactfc_350_pci_eth
phoenix_contactilc_1x0
phoenix_contactilc_1x1
phoenix_contactilc_1x1_gsm_gprs
phoenix_contactilc_3xx
phoenix_contactpc_worx_rt_basic
phoenix_contactpc_worx_srt
phoenix_contactrfc_430_eth-ib
phoenix_contactrfc_450_eth-ib
phoenix_contactrfc_460r_pn_3tx
phoenix_contactrfc_460r_pn_3tx-s
phoenix_contactrfc_470_pn_3tx
phoenix_contactrfc_470s_pn_3tx
phoenix_contactrfc_480s_pn_4tx

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability allows unauthenticated remote upload of arbitrary/malicious logic to affected Phoenix Contact Classic Line Controllers (ILC, AXC, RFC, PC WORX, FC product families) running ProConOS/ProConOS eCLR; monitor for unexpected or unauthenticated logic upload attempts to these devices over the network.
  • The affected devices lack integrity and authenticity checks on uploaded logic; any logic upload that does not originate from a known, authenticated engineering workstation in a protected environment should be treated as suspicious.
  • No known public exploits exist at time of advisory; focus detection on anomalous engineering-tool-to-controller communication (e.g., unexpected source IPs initiating logic downloads to PLC TCP ports used by ProConOS).

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.