Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12870

Опубликовано: 24 июн. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized Pointer and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phoenixcontact:automationworx_software_suite:*:*:*:*:*:*:*:*
Версия до 1.86 (включая)

EPSS

Процентиль: 82%
0.01728
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-824

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized Pointer and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

CVSS3: 8.8
fstec
больше 6 лет назад

Уязвимость компонентов PC Worx, PC Worx Express, INTERBUS Config+ программного пакета Automationworx Software Suite, связанная доступом к неинициализированному указателю, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 82%
0.01728
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-824