CVE-2021-34597: Phoenix Contact: PC Worx/-Express prone to improper input validation vulnerability
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34597?
CVE-2021-34597 is an Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88.
How does CVE-2021-34597 impact me?
CVE-2021-34597 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.
What is the severity of CVE-2021-34597?
The severity of CVE-2021-34597 is high (CVSS score: 7.8).
Which software versions are affected by CVE-2021-34597?
PC Worx Automation Suite of Phoenix Contact up to version 1.88 and PC Worx Express up to version 1.88 are affected by CVE-2021-34597.
How can I fix CVE-2021-34597?
To fix CVE-2021-34597, it is recommended to update PC Worx Automation Suite and PC Worx Express to a version beyond 1.88.