CVE-2019-9201: Critical severity Phoenixcontact Ilc 131 Eth Firmware vulnerability
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-9201.
What is the affected software?
The affected software includes Phoenixcontact Ilc 131 Eth Firmware, Phoenixcontact Ilc 131 Eth\/xc Firmware, Phoenixcontact Ilc 151 Eth Firmware, Phoenixcontact Ilc 151 Eth\/xc Firmware, Phoenixcontact Ilc 171 Eth 2tx Firmware, Phoenixcontact Ilc 191 Eth 2tx Firmware, Phoenixcontact Ilc 191 Me\/an Firmware, and Phoenixcontact Axc 1050 Firmware.
What is the severity of CVE-2019-9201?
The severity of CVE-2019-9201 is critical with a CVSS score of 9.8.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by establishing TCP sessions to port 1962 on vulnerable Phoenix Contact devices and obtain sensitive information or make changes.
Are there any references for further information on this vulnerability?
Yes, you can find further information on this vulnerability at the following references: [VDE-2019-015 advisory](https://cert.vde.com/en/advisories/VDE-2019-015/) and [Medium article by Sergiu Sechel](https://medium.com/@SergiuSechel/misconfiguration-in-ilc-gsm-gprs-devices-leaves-over-1-200-ics-devices-vulnerable-to-attacks-over-82c2d4a91561).