First published: Tue Feb 26 2019(Updated: )
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Phoenix Contact ILC 131 ETH Firmware | ||
Phoenix Contact ILC 131 ETH/XC | ||
All of | ||
Phoenix Contact ILC 131 ETH/XC Firmware | ||
Phoenix Contact ILC 131 ETH/XC | ||
All of | ||
Phoenix Contact ILC 151 ETH Firmware | ||
Phoenix Contact ILC 151 ETH Firmware | ||
All of | ||
Phoenix Contact ILC 151 ETH/XC Firmware | ||
Phoenix Contact ILC 151 ETH/XC | ||
All of | ||
Phoenix Contact ILC 171 ETH 2TX Firmware | ||
Phoenix Contact ILC 171 ETH 2TX | ||
All of | ||
Phoenix Contact ILC 191 ETH 2TX | ||
Phoenix Contact ILC 191 ETH 2TX | ||
All of | ||
Phoenix Contact ILC 191 ME/AN Firmware | ||
Phoenix Contact ILC 191 ME/AN | ||
All of | ||
Phoenix Contact Axc 1050 Firmware | ||
Phoenix Contact Axc 1050 Firmware | ||
Phoenix Contact ILC 131 ETH Firmware | ||
Phoenix Contact ILC 131 ETH/XC | ||
Phoenix Contact ILC 131 ETH/XC Firmware | ||
Phoenix Contact ILC 131 ETH/XC | ||
Phoenix Contact ILC 151 ETH Firmware | ||
Phoenix Contact ILC 151 ETH Firmware | ||
Phoenix Contact ILC 151 ETH/XC Firmware | ||
Phoenix Contact ILC 151 ETH/XC | ||
Phoenix Contact ILC 171 ETH 2TX Firmware | ||
Phoenix Contact ILC 171 ETH 2TX | ||
Phoenix Contact ILC 191 ETH 2TX | ||
Phoenix Contact ILC 191 ETH 2TX | ||
Phoenix Contact ILC 191 ME/AN Firmware | ||
Phoenix Contact ILC 191 ME/AN | ||
Phoenix Contact Axc 1050 Firmware | ||
Phoenix Contact Axc 1050 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-9201.
The affected software includes Phoenixcontact Ilc 131 Eth Firmware, Phoenixcontact Ilc 131 Eth\/xc Firmware, Phoenixcontact Ilc 151 Eth Firmware, Phoenixcontact Ilc 151 Eth\/xc Firmware, Phoenixcontact Ilc 171 Eth 2tx Firmware, Phoenixcontact Ilc 191 Eth 2tx Firmware, Phoenixcontact Ilc 191 Me\/an Firmware, and Phoenixcontact Axc 1050 Firmware.
The severity of CVE-2019-9201 is critical with a CVSS score of 9.8.
An attacker can exploit this vulnerability by establishing TCP sessions to port 1962 on vulnerable Phoenix Contact devices and obtain sensitive information or make changes.
Yes, you can find further information on this vulnerability at the following references: [VDE-2019-015 advisory](https://cert.vde.com/en/advisories/VDE-2019-015/) and [Medium article by Sergiu Sechel](https://medium.com/@SergiuSechel/misconfiguration-in-ilc-gsm-gprs-devices-leaves-over-1-200-ics-devices-vulnerable-to-attacks-over-82c2d4a91561).