CVE-2020-12518

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
17/12/2020
Last modified:
21/12/2020

Description

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* 2021.0 (excluding)
cpe:2.3:h:phoenixcontact:axc_f_1152:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* 2021.0 (excluding)
cpe:2.3:h:phoenixcontact:axc_f_2152:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* 2021.0 (excluding)
cpe:2.3:h:phoenixcontact:axc_f_3152:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* 2021.0 (excluding)
cpe:2.3:h:phoenixcontact:rfc_4072s:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* 2021.0 (excluding)
cpe:2.3:h:phoenixcontact:axc_f_2152_starterkit:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* 2021.0 (excluding)
cpe:2.3:h:phoenixcontact:plcnext_technology_starterkit:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools