Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical Function
Summary
| CVE | CVE-2014-9195 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-17 02:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: CWE-306 | CWE-255 | CWE-306 CWE-306
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | [email protected] | Secondary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C | |
| 2.0 | CNA | CVSS | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phoenixcontact-software | Multiprog | 5.0 | All | All | All |
| Application | Phoenixcontact-software | Multiprog | 5.0 | All | All | All |
| Application | Phoenixcontact-software | Multiprog | 5.0 | All | All | All |
| Operating System | Phoenixcontact-software | Proconos Eclr | All | All | All | All |
| Operating System | Phoenixcontact-software | Proconos Eclr | All | All | All | All |
| Operating System | Phoenixcontact-software | Proconos Eclr | All | All | All | All |
| Operating System | Phoenixcontact-software | Proconos Eclr | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Phoenix Contact | ProConOs | affected All versions | Not specified |
| CNA | Phoenix Contact | MultiProg | affected All versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Phoenix Contact Software ProConOs and MultiProg Authentication Vulnerability | CISA | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| Phoenix Contact ILC 150 ETH PLC - Remote Control Script - Hardware remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Third Party Advisory, VDB Entry |
| www.cisa.gov/news-events/ics-advisories/icsa-15-013-03 | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Reid Wightman of Digital Bond (en)
Additional Advisory Data
Workarounds
CNA: Phoenix Contact Software designed the applications and protocols without authentication mechanisms. It is the understanding of Phoenix Contact Software that vendors using the application software and its protocol would incorporate its own authentication mechanism in its final product. Phoenix Contact Software is considering adding authentication software into future versions of its application software and its protocol.
There are currently no legacy QID mappings associated with this CVE.