HIGH · 7.8

CVE-2021-34597

Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of t...

Vulnerability Description

Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
PhoenixcontactPc Worx<= 1.88
PhoenixcontactPc Worx Express<= 1.88

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-34597?

CVE-2021-34597 is a vulnerability with a CVSS score of 7.8 (HIGH). Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of t...

How severe is CVE-2021-34597?

CVE-2021-34597 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-34597?

Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Pc Worx, Phoenixcontact Pc Worx Express.