9.8
CVSSv3

CVE-2022-31800

Published: 21/06/2022 Updated: 28/06/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact axc_1050_firmware

phoenixcontact axc_1050_xc_firmware

phoenixcontact axc_3050_firmware

phoenixcontact fc_350_pci_eth_firmware

phoenixcontact ilc1x0_firmware

phoenixcontact ilc1x1_firmware

phoenixcontact ilc_1x1_gsm\\/gprs_firmware

phoenixcontact ilc_3xx_firmware

phoenixcontact pc_worx_rt_basic_firmware

phoenixcontact pc_worx_srt_firmware

phoenixcontact rfc_430_eth-ib_firmware

phoenixcontact rfc_450_eth-ib_firmware

phoenixcontact rfc_460r_pn_3tx_firmware

phoenixcontact rfc_460r_pn_3tx-s_firmware

phoenixcontact rfc_470_pn_3tx_firmware

phoenixcontact rfc_470s_pn_3tx_firmware

phoenixcontact rfc_480s_pn_4tx_firmware

Recent Articles

What to do about inherent security flaws in critical infrastructure?
The Register • Jessica Lyons Hardcastle • 01 Jan 1970

Topics Security Off-Prem On-Prem Software Offbeat Vendor Voice Vendor Voice Resources Industrial systems' security got 99 problems and CVEs are one. Or more

The latest threat security research into operational technology (OT) and industrial systems identified a bunch of issues — 56 to be exact — that criminals could use to launch cyberattacks against critical infrastructure.  But many of them are unfixable, due to insecure protocols and architectural designs. And this highlights a larger security problem with devices that control electric grids and keep clean water flowing through faucets, according to some industrial cybersecurity experts....