CVE-2020-12498 – Phoenix Contact Automation Worx <= 1.87: out-of-bounds read remote code execution
https://notcve.org/view.php?id=CVE-2020-12498
mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation. El análisis de archivos mwe en Phoenix Contact PC Worx y PC Worx Express versiones 1.87 y anteriores, es vulnerable a una ejecución de código remota de lectura fuera de límites. Los proyectos manipulados de PC Worx podría conllevar a una ejecución de código remota debido a una comprobación de datos de entrada insuficiente This vulnerability allows remote attackers to execute arbitrary code on affected installations of Phoenix Contact Automationworx. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of MWE files by the PC WORX and PC WORX Express executables. • https://cert.vde.com/de-de/advisories/vde-2020-023 https://www.zerodayinitiative.com/advisories/ZDI-20-826 • CWE-121: Stack-based Buffer Overflow CWE-125: Out-of-bounds Read •
CVE-2020-12497 – Phoenix Contact Automation Worx <= 1.87: stack-based overflow
https://notcve.org/view.php?id=CVE-2020-12497
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation. El análisis de archivos XML de PLCopen en Phoenix Contact PC Worx y PC Worx Express versiones 1.87 y anteriores, puede conllevar un desbordamiento en la región stack de la memoria. Los proyectos manipulados de PC Worx podrían conducir a una ejecución de código remota debido a una comprobación de datos de entrada insuficiente This vulnerability allows remote attackers to execute arbitrary code on affected installations of Phoenix Contact Automationworx. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PLCOpen XML files. • https://cert.vde.com/de-de/advisories/vde-2020-023 https://www.zerodayinitiative.com/advisories/ZDI-20-825 https://www.zerodayinitiative.com/advisories/ZDI-21-398 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •
CVE-2020-10939
https://notcve.org/view.php?id=CVE-2020-10939
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation. Permisos de ruta predeterminados y no seguros en PHOENIX CONTACT PC WORX SRT versiones hasta 1.14, permiten una escalada de privilegios local. • https://cert.vde.com/en-us/advisories/vde-2020-012 • CWE-276: Incorrect Default Permissions •
CVE-2019-16675 – Phoenix Contact Automationworx MWT File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2019-16675
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation. Se detectó un problema en PHOENIX CONTACT PC Worx versiones hasta 1.86, PC Worx Express versiones hasta 1.86 y Config+ versiones hasta 1.86. • https://cert.vde.com/en-us/advisories https://www.us-cert.gov/ics/advisories/icsa-19-302-01 https://www.zerodayinitiative.com/advisories/ZDI-19-922 https://www.zerodayinitiative.com/advisories/ZDI-19-991 • CWE-125: Out-of-bounds Read •