Vulnerability Description
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phoenixcontact | Ilc 131 Eth Firmware | - |
| Phoenixcontact | Ilc 131 Eth | - |
| Phoenixcontact | Ilc 131 Eth\/Xc Firmware | - |
| Phoenixcontact | Ilc 131 Eth\/Xc | - |
| Phoenixcontact | Ilc 151 Eth Firmware | - |
| Phoenixcontact | Ilc 151 Eth | - |
| Phoenixcontact | Ilc 151 Eth\/Xc Firmware | - |
| Phoenixcontact | Ilc 151 Eth\/Xc | - |
| Phoenixcontact | Ilc 171 Eth 2Tx Firmware | - |
| Phoenixcontact | Ilc 171 Eth 2Tx | - |
| Phoenixcontact | Ilc 191 Eth 2Tx Firmware | - |
| Phoenixcontact | Ilc 191 Eth 2Tx | - |
| Phoenixcontact | Ilc 191 Me\/An Firmware | - |
| Phoenixcontact | Ilc 191 Me\/An | - |
| Phoenixcontact | Axc 1050 Firmware | - |
| Phoenixcontact | Axc 1050 | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en/advisories/VDE-2019-015/Third Party Advisory
- https://medium.com/%40SergiuSechel/misconfiguration-in-ilc-gsm-gprs-devices-leavExploit
- https://cert.vde.com/en/advisories/VDE-2019-015/Third Party Advisory
- https://medium.com/%40SergiuSechel/misconfiguration-in-ilc-gsm-gprs-devices-leavExploit
FAQ
What is CVE-2019-9201?
CVE-2019-9201 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to t...
How severe is CVE-2019-9201?
CVE-2019-9201 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-9201?
Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Ilc 131 Eth Firmware, Phoenixcontact Ilc 131 Eth, Phoenixcontact Ilc 131 Eth\/Xc Firmware, Phoenixcontact Ilc 131 Eth\/Xc, Phoenixcontact Ilc 151 Eth Firmware.