7.3
CVSSv3

CVE-2016-8380

Published: 05/04/2018 Updated: 14/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact ilc_plcs_firmware -

Exploits

# Exploit Title: Phoenix Contact WebVisit 2985725 - Authentication Bypass # Date: 2018-09-30 # Exploit Author: Deneut Tijl # Vendor Homepage: wwwphoenixcontactcom # Software Link: wwwphoenixcontactcom/online/portal/nl/?uri=pxc-oc-itemdetail:pid=2985725&library=nlnl&pcck=P-19-05-01&tab=5 # Version: WebVisit (all versions) # C ...
Phoenix Contact WebVisit 2985725 suffers from an authentication bypass vulnerability ...