CVE-2018-16994
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 devices and Bosch Rexroth S20-ETH-BK and Rexroth S20-PN-BK+ (the S20-PN-BK+/S20-ETH-BK fieldbus couplers sold by Bosch Rexroth contain technology from Phoenix Contact). Incorrect handling of a request with non-standard symbols allows remote attackers to initiate a complete lock up of the bus coupler. Authentication of the request is not required.
Se descubrió un problema en PHOENIX CONTACT AXL F BK PN anterior o igual 1.0.4, AXL F BK ETH anterior o igual 1.12 y dispositivos AXL F BK ETH XC anterior o igual 1.11 y Bosch Rexroth S20-ETH-BK y Rexroth S20-PN-BK + (los acopladores de bus de campo S20-PN-BK + / S20-ETH-BK vendidos por Bosch Rexroth contienen tecnología de Phoenix Contact). El manejo incorrecto de una solicitud con símbolos no estándar permite a los atacantes remotos iniciar un bloqueo completo del acoplador del bus. No se requiere autenticación de la solicitud.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-09-13 CVE Reserved
- 2020-02-18 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://psirt.bosch.com/security-advisories/bosch-sa-645125.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phoenixcontact Search vendor "Phoenixcontact" | Axl F Bk Pn Firmware Search vendor "Phoenixcontact" for product "Axl F Bk Pn Firmware" | <= 1.0.4 Search vendor "Phoenixcontact" for product "Axl F Bk Pn Firmware" and version " <= 1.0.4" | - |
Affected
| in | Phoenixcontact Search vendor "Phoenixcontact" | Axl F Bk Pn Search vendor "Phoenixcontact" for product "Axl F Bk Pn" | - | - |
Safe
|
Phoenixcontact Search vendor "Phoenixcontact" | Axl F Bk Eth Firmware Search vendor "Phoenixcontact" for product "Axl F Bk Eth Firmware" | <= 1.12 Search vendor "Phoenixcontact" for product "Axl F Bk Eth Firmware" and version " <= 1.12" | - |
Affected
| in | Phoenixcontact Search vendor "Phoenixcontact" | Axl F Bk Eth Search vendor "Phoenixcontact" for product "Axl F Bk Eth" | - | - |
Safe
|
Phoenixcontact Search vendor "Phoenixcontact" | Axl F Bk Eth Xc Firmware Search vendor "Phoenixcontact" for product "Axl F Bk Eth Xc Firmware" | <= 1.11 Search vendor "Phoenixcontact" for product "Axl F Bk Eth Xc Firmware" and version " <= 1.11" | - |
Affected
| in | Phoenixcontact Search vendor "Phoenixcontact" | Axl F Bk Eth Xc Search vendor "Phoenixcontact" for product "Axl F Bk Eth Xc" | - | - |
Safe
|