First published: Tue Aug 03 2021(Updated: )
Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenix Contact PLCnext Technology Starterkit Firmware | <2021.0.5 | |
Phoenix Contact PLCnext Technology Starterkit Firmware | ||
phoenixcontact axc f 2152 starterkit firmware | <2021.0.5 | |
phoenixcontact axc f 2152 starterkit | ||
Phoenix Contact RFC 4072S | <2021.0.5 | |
Phoenix Contact RFC 4072S | ||
Phoenix Contact AXC F 3152 Firmware | <2021.0.5 | |
Phoenix Contact AXC F 3152 Firmware | ||
Phoenix Contact Axc F 1152 | <2021.0.5 | |
Phoenix Contact Axc F 1152 | ||
Phoenix Contact Axioline F AXL F 2152 Firmware | <2021.0.5 | |
Phoenix Contact Axioline F AXL F 2152 Firmware |
Phoenix Contact recommends affected users to upgrade to the current Firmware 2021.0.5 LTS or higher which fixes this vulnerability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34570 is a vulnerability that affects multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS.
CVE-2021-34570 has a severity rating of 7.5 (High).
Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are affected by CVE-2021-34570.
CVE-2021-34570 can be exploited through specially crafted JSON requests.
Updating the affected Phoenix Contact PLCnext control devices to version 2021.0.5 LTS will fix CVE-2021-34570.