6.8
CVSSv2

CVE-2019-12871

Published: 24/06/2019 Updated: 27/06/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in PHOENIX CONTACT PC Worx up to and including 1.86, PC Worx Express up to and including 1.86, and Config+ up to and including 1.86. A manipulated PC Worx or Config+ project file could lead to a Use-After-Free and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact automationworx software suite