7.3
CVSSv3

CVE-2016-8371

Published: 05/04/2018 Updated: 14/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact ilc_plcs_firmware -

Exploits

# Exploit Title: Phoenix Contact WebVisit 2985725 - Authentication Bypass # Date: 2018-09-30 # Exploit Author: Deneut Tijl # Vendor Homepage: wwwphoenixcontactcom # Software Link: wwwphoenixcontactcom/online/portal/nl/?uri=pxc-oc-itemdetail:pid=2985725&library=nlnl&pcck=P-19-05-01&tab=5 # Version: WebVisit (all versions) # C ...
Phoenix Contact WebVisit 2985725 suffers from an authentication bypass vulnerability ...