CVE-2022-31800
published 2022-06-21CVE-2022-31800: An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.46%
70.5th percentile
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | axc_1050 | — | — |
| phoenix_contact | axc_1050_xc | — | — |
| phoenix_contact | axc_3050 | — | — |
| phoenix_contact | fc_350_pci_eth | — | — |
| phoenix_contact | ilc_1x0 | — | — |
| phoenix_contact | ilc_1x1 | — | — |
| phoenix_contact | ilc_1x1_gsm_gprs | — | — |
| phoenix_contact | ilc_3xx | — | — |
| phoenix_contact | pc_worx_rt_basic | — | — |
| phoenix_contact | pc_worx_srt | — | — |
| phoenix_contact | rfc_430_eth-ib | — | — |
| phoenix_contact | rfc_450_eth-ib | — | — |
| phoenix_contact | rfc_460r_pn_3tx | — | — |
| phoenix_contact | rfc_460r_pn_3tx-s | — | — |
| phoenix_contact | rfc_470_pn_3tx | — | — |
| phoenix_contact | rfc_470s_pn_3tx | — | — |
| phoenix_contact | rfc_480s_pn_4tx | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability allows unauthenticated remote upload of arbitrary/malicious logic to affected Phoenix Contact Classic Line Controllers (ILC, AXC, RFC, PC WORX, FC product families) running ProConOS/ProConOS eCLR; monitor for unexpected or unauthenticated logic upload attempts to these devices over the network. ↗
- →The affected devices lack integrity and authenticity checks on uploaded logic; any logic upload that does not originate from a known, authenticated engineering workstation in a protected environment should be treated as suspicious. ↗
- →No known public exploits exist at time of advisory; focus detection on anomalous engineering-tool-to-controller communication (e.g., unexpected source IPs initiating logic downloads to PLC TCP ports used by ProConOS). ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Phoenix Contact Classic Line Controllers
cisa_ics·2022-06-21·CVSS 9.8
[CRITICAL] Phoenix Contact Classic Line Controllers
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Phoenix Contact Classic Line Controllers
Last RevisedJune 21, 2022
Alert CodeICSA-22-172-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Phoenix Contact
- Equipment: ILC, AXC, RFC, PC WORX, FC
- Vulnerability: Insufficient Verification of Data Authenticity
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to upload logic with arbitrary code.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of the classic line industrial controllers, are affected:
GHSA
GHSA-m7x4-j34m-52hc: An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the dev
ghsa_unreviewed·2022-06-22
CVE-2022-31800 [CRITICAL] CWE-345 GHSA-m7x4-j34m-52hc: An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the dev
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
No detection rules found.
No public exploits indexed.
2022-06-21
Published