Lucene search

K
nvd[email protected]NVD:CVE-2022-3461
HistoryNov 15, 2022 - 11:15 a.m.

CVE-2022-3461

2022-11-1511:15:10
CWE-119
web.nvd.nist.gov
4
phoenix contact
automationworx
software suite
vulnerability
heap buffer overflow
read access violation
attack
confidentiality

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

30.3%

In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.

Affected configurations

Nvd
Node
phoenixcontactautomationworx_software_suiteMatch1.89
VendorProductVersionCPE
phoenixcontactautomationworx_software_suite1.89cpe:2.3:a:phoenixcontact:automationworx_software_suite:1.89:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

30.3%

Related for NVD:CVE-2022-3461