CVE-2020-12517: Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).
Published Dec 17, 2020
·Updated
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).
Affected Software
7 affected components
Phoenixcontact Plcnext Firmware<2021.0
Phoenixcontact Axc F 1152
Phoenixcontact Axc F 2152
Phoenixcontact Axc F 3152
Phoenixcontact Rfc 4072s
Phoenixcontact Axc F 2152 Starterkit
Phoenixcontact Plcnext Technology Starterkit
Remediation
Information
Phoenix Contact recommends affected users to upgrade to the current Firmware 2021.0 LTS or higher which fixes these vulnerabilities.
Event History
Dec 17, 2020
CVE Published
via MITRE·10:43 PM
Data Sourced
via MITRE·10:43 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-12517?
CVE-2020-12517 is a vulnerability found in Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS.
2
What is the severity of CVE-2020-12517?
CVE-2020-12517 has a severity rating of critical.
3
How can an attacker exploit CVE-2020-12517?
An authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website.
4
Which software versions are affected by CVE-2020-12517?
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS are affected by CVE-2020-12517.
5
Is Phoenix Contact Axc F 1152 affected by CVE-2020-12517?
No, Phoenix Contact Axc F 1152 is not vulnerable to CVE-2020-12517.