Missing Authentication for Critical Function in Phoenix Contact GmbH products - CVE-2019-9201

 

Missing Authentication for Critical Function in Phoenix Contact GmbH products - CVE-2019-9201

Published: June 22, 2022


Vulnerability identifier: #VU64578
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9201
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected product does not feature a function to authenticate communication protocols. A remote attacker can change or download the configuration, start or stop services, update or modify the firmware or shut down the device.


Affected software

ILC 1x0
RFC 480S
PC WORX RT BASIC
RFC 460R
AXC 1050
AXC 3050
AXC 1050XC
RFC 430 ETH
RFC 450 ETH
FC 350 PCI ETH
RFC 470S
ILC 3xx
ILC 1x1
PC WORX SRT

How to mitigate CVE-2019-9201

Install updates from vendor's website.

AXC 1050 - addressed in versions 3.01, 5.00
AXC 3050 - addressed in versions 5.60, 6.30
AXC 1050XC - addressed in versions 3.01, 5.00
ILC 3xx - update to 3.98
ILC 1x1 - update to 4.42

External References

Related Security Bulletins