CVE-2022-31801: Insufficient Verification of Data Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering tool
Published Jun 21, 2022
·Updated
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
Affected Software
3 affected components
Phoenixcontact Multiprog
Phoenixcontact Proconos
Phoenixcontact-software Proconos Eclr
Event History
Jun 21, 2022
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
DescriptionSeverityWeakness
Sep 8, 58389
Event
02:29 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-31801.
2
What is the severity of CVE-2022-31801?
The severity of CVE-2022-31801 is critical with a score of 9.8.
3
Which software is affected by CVE-2022-31801?
The software affected by CVE-2022-31801 are Phoenixcontact Multiprog, Phoenixcontact Proconos, and Phoenixcontact-software Proconos Eclr.
4
How can an attacker exploit CVE-2022-31801?
An unauthenticated remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
5
Is there a fix available for CVE-2022-31801?
Unfortunately, there is no information available about a fix for CVE-2022-31801 at the moment.