First published: Tue Feb 26 2019(Updated: )
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenixcontact Ilc 131 Eth Firmware | ||
Phoenixcontact Ilc 131 Eth | ||
Phoenixcontact Ilc 131 Eth\/xc Firmware | ||
Phoenixcontact Ilc 131 Eth\/xc | ||
Phoenixcontact Ilc 151 Eth Firmware | ||
Phoenixcontact Ilc 151 Eth | ||
Phoenixcontact Ilc 151 Eth\/xc Firmware | ||
Phoenixcontact Ilc 151 Eth\/xc | ||
Phoenixcontact Ilc 171 Eth 2tx Firmware | ||
Phoenixcontact Ilc 171 Eth 2tx | ||
Phoenixcontact Ilc 191 Eth 2tx Firmware | ||
Phoenixcontact Ilc 191 Eth 2tx | ||
Phoenixcontact Ilc 191 Me\/an Firmware | ||
Phoenixcontact Ilc 191 Me\/an | ||
Phoenixcontact Axc 1050 Firmware | ||
Phoenixcontact Axc 1050 | ||
All of | ||
Phoenixcontact Ilc 131 Eth Firmware | ||
Phoenixcontact Ilc 131 Eth | ||
All of | ||
Phoenixcontact Ilc 131 Eth\/xc Firmware | ||
Phoenixcontact Ilc 131 Eth\/xc | ||
All of | ||
Phoenixcontact Ilc 151 Eth Firmware | ||
Phoenixcontact Ilc 151 Eth | ||
All of | ||
Phoenixcontact Ilc 151 Eth\/xc Firmware | ||
Phoenixcontact Ilc 151 Eth\/xc | ||
All of | ||
Phoenixcontact Ilc 171 Eth 2tx Firmware | ||
Phoenixcontact Ilc 171 Eth 2tx | ||
All of | ||
Phoenixcontact Ilc 191 Eth 2tx Firmware | ||
Phoenixcontact Ilc 191 Eth 2tx | ||
All of | ||
Phoenixcontact Ilc 191 Me\/an Firmware | ||
Phoenixcontact Ilc 191 Me\/an | ||
All of | ||
Phoenixcontact Axc 1050 Firmware | ||
Phoenixcontact Axc 1050 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-9201.
The affected software includes Phoenixcontact Ilc 131 Eth Firmware, Phoenixcontact Ilc 131 Eth\/xc Firmware, Phoenixcontact Ilc 151 Eth Firmware, Phoenixcontact Ilc 151 Eth\/xc Firmware, Phoenixcontact Ilc 171 Eth 2tx Firmware, Phoenixcontact Ilc 191 Eth 2tx Firmware, Phoenixcontact Ilc 191 Me\/an Firmware, and Phoenixcontact Axc 1050 Firmware.
The severity of CVE-2019-9201 is critical with a CVSS score of 9.8.
An attacker can exploit this vulnerability by establishing TCP sessions to port 1962 on vulnerable Phoenix Contact devices and obtain sensitive information or make changes.
Yes, you can find further information on this vulnerability at the following references: [VDE-2019-015 advisory](https://cert.vde.com/en/advisories/VDE-2019-015/) and [Medium article by Sergiu Sechel](https://medium.com/@SergiuSechel/misconfiguration-in-ilc-gsm-gprs-devices-leaves-over-1-200-ics-devices-vulnerable-to-attacks-over-82c2d4a91561).