CVE-2020-12498
Phoenix Contact Automation Worx <= 1.87: out-of-bounds read remote code execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.
El análisis de archivos mwe en Phoenix Contact PC Worx y PC Worx Express versiones 1.87 y anteriores, es vulnerable a una ejecución de código remota de lectura fuera de límites. Los proyectos manipulados de PC Worx podría conllevar a una ejecución de código remota debido a una comprobación de datos de entrada insuficiente
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Phoenix Contact Automationworx. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of MWE files by the PC WORX and PC WORX Express executables. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-30 CVE Reserved
- 2020-07-01 CVE Published
- 2024-04-20 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-121: Stack-based Buffer Overflow
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-20-826 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert.vde.com/de-de/advisories/vde-2020-023 | 2020-07-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phoenixcontact Search vendor "Phoenixcontact" | Pc Worx Search vendor "Phoenixcontact" for product "Pc Worx" | < 1.87 Search vendor "Phoenixcontact" for product "Pc Worx" and version " < 1.87" | - |
Affected
| ||||||
Phoenixcontact Search vendor "Phoenixcontact" | Pc Worx Express Search vendor "Phoenixcontact" for product "Pc Worx Express" | <= 1.87 Search vendor "Phoenixcontact" for product "Pc Worx Express" and version " <= 1.87" | - |
Affected
|