CVE-2020-12521
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
17/12/2020
Last modified:
21/12/2020
Description
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system services or a complete reboot.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
6.10
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* | 2021.0 (excluding) | |
| cpe:2.3:h:phoenixcontact:axc_f_1152:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* | 2021.0 (excluding) | |
| cpe:2.3:h:phoenixcontact:axc_f_2152:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* | 2021.0 (excluding) | |
| cpe:2.3:h:phoenixcontact:axc_f_3152:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* | 2021.0 (excluding) | |
| cpe:2.3:h:phoenixcontact:rfc_4072s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* | 2021.0 (excluding) | |
| cpe:2.3:h:phoenixcontact:axc_f_2152_starterkit:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:phoenixcontact:plcnext_firmware:*:*:*:*:long_term_support:*:*:* | 2021.0 (excluding) | |
| cpe:2.3:h:phoenixcontact:plcnext_technology_starterkit:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



