CVE-2022-3737
published 2022-11-15CVE-2022-3737: In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.20%
10.5th percentile
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | config | <= 1.89 | — |
| phoenix_contact | pc_worx | <= 1.89 | — |
| phoenix_contact | pc_worx_express | <= 1.89 | — |
| phoenixcontact | automationworx_software_suite | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r2cg-cw4r-gcx4: In PHOENIX CONTACT Automationworx Software Suite up to version 1
ghsa_unreviewed·2022-11-15
CVE-2022-3737 [HIGH] CWE-125 GHSA-r2cg-cw4r-gcx4: In PHOENIX CONTACT Automationworx Software Suite up to version 1
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
CISA ICS
Phoenix Contact Automation Worx
cisa_ics·2022-11-22·CVSS 7.8
[HIGH] Phoenix Contact Automation Worx
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Phoenix Contact Automation Worx
Last RevisedNovember 22, 2022
Alert CodeICSA-22-326-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Phoenix Contact
- Equipment: Automation Worx Software Suite
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could lead to a heap buffer overflow, release of unallocated memory, or a read access violation.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following comp
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-15
Published