Lucene search

K
nvd[email protected]NVD:CVE-2022-3737
HistoryNov 15, 2022 - 11:15 a.m.

CVE-2022-3737

2022-11-1511:15:12
CWE-125
web.nvd.nist.gov
3
phoenix contact
automationworx software suite
input validation
vulnerability
memory read
workstation security

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

26.4%

In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.

Affected configurations

Nvd
Node
phoenixcontactautomationworx_software_suiteMatch1.89
VendorProductVersionCPE
phoenixcontactautomationworx_software_suite1.89cpe:2.3:a:phoenixcontact:automationworx_software_suite:1.89:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

26.4%

Related for NVD:CVE-2022-3737