CVE-2022-3737: Out-of-bounds Read in PHOENIX CONTACT Automationworx Software Suite
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PHOENIX CONTACT Automationworx Software Suiteto a version that resolves this vulnerability.Fixed in 1.89Patch Automation Worx Software Suite > 1.89
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3737?
The severity of CVE-2022-3737 is high with a CVSS score of 7.8.
How does CVE-2022-3737 impact PHOENIX CONTACT Automationworx Software Suite?
CVE-2022-3737 can compromise the availability, integrity, or confidentiality of an application programming workstation using PHOENIX CONTACT Automationworx Software Suite up to version 1.89.
What is the affected version of PHOENIX CONTACT Automationworx Software Suite?
The affected version of PHOENIX CONTACT Automationworx Software Suite is 1.89.
How can an attacker exploit CVE-2022-3737?
An attacker can exploit CVE-2022-3737 by using insufficiently validated input data to read memory beyond the intended scope.
Is there a fix available for CVE-2022-3737?
It is recommended to update to a version of PHOENIX CONTACT Automationworx Software Suite that is not affected by CVE-2022-3737. Please refer to the vendor's advisory for more information.