CVE-2020-12521: Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system services or a complete reboot.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-12521?
CVE-2020-12521 is a vulnerability on Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS that can lead to a high system load in the PROFINET stack and potentially cause failure of system services or a complete reboot.
How does CVE-2020-12521 affect Phoenix Contact PLCnext Control Devices?
CVE-2020-12521 affects Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS.
What is the severity of CVE-2020-12521?
CVE-2020-12521 has a severity rating of 6.5 (Medium).
How can an attacker exploit CVE-2020-12521?
An attacker can exploit CVE-2020-12521 by sending a specially crafted LLDP packet.
Is there a fix for CVE-2020-12521?
Yes, updating to Phoenix Contact PLCnext Control Devices version 2021.0 LTS or later will fix CVE-2020-12521.