CVE-2020-9435: High severity Phoenixcontact Tc Router 3002t-4g Firmware vulnerability
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by default for web-based services on the device. Impersonation, man-in-the-middle, or passive decryption attacks are possible if the generic certificate is not replaced by a device-specific certificate during installation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
During installation, ensure the generic certificate used by default for web-based services is replaced with a device-specific certificate (the devices listed contain a hardcoded certificate and key used by default for web-based services).
PHOENIX CONTACT TC ROUTER 3002T-4G / TC ROUTER 2002T-3G / TC ROUTER 3002T-4G VZW / TC ROUTER 3002T-4G ATT / TC CLOUD CLIENT 1002-4G / TC CLOUD CLIENT 1002-TXTX web-based services device-specific certificate (replace hardcoded default) = Replace the generic/hardcoded certificate and key with a device-specific certificate during installation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9435?
The severity of CVE-2020-9435 is high with a score of 7.5.
What are the affected devices of CVE-2020-9435?
The affected devices of CVE-2020-9435 are PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17.
What is the vulnerability type of CVE-2020-9435?
The vulnerability type of CVE-2020-9435 is a hardcoded certificate and key.
How do I fix the vulnerability in PHOENIX CONTACT TC ROUTER 3002T-4G?
To fix the vulnerability in PHOENIX CONTACT TC ROUTER 3002T-4G, update the firmware to version 2.05.3 or higher.
Where can I find more information about CVE-2020-9435?
You can find more information about CVE-2020-9435 at the following references: [Reference 1](http://packetstormsecurity.com/files/156729/Phoenix-Contact-TC-Router-TC-Cloud-Client-Command-Injection.html), [Reference 2](http://seclists.org/fulldisclosure/2020/Mar/15), [Reference 3](https://cert.vde.com/en-us/advisories/).