Lucene search

K
cveCERTVDECVE-2020-12499
HistoryJul 21, 2020 - 3:15 p.m.

CVE-2020-12499

2020-07-2115:15:13
CWE-22
CERTVDE
web.nvd.nist.gov
19
phoenix contact
plcnext engineer
version 2020.3.1
improper path sanitation
vulnerability
nvd

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0

Percentile

9.9%

In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.

Affected configurations

Nvd
Node
phoenixcontactplcnext_engineerRange2020-3-1
VendorProductVersionCPE
phoenixcontactplcnext_engineer*cpe:2.3:a:phoenixcontact:plcnext_engineer:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "PLCnext Engineer",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "lessThanOrEqual": "2020.3.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0

Percentile

9.9%

Related for CVE-2020-12499