CVE-2020-12524
Summary
| CVE | CVE-2020-12524 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-02 15:15:00 UTC |
| Updated | 2020-12-04 21:45:00 UTC |
| Description | Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service). |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Phoenixcontact | Btp 2043w | - | All | All | All |
| Hardware | Phoenixcontact | Btp 2043w | - | All | All | All |
| Operating System | Phoenixcontact | Btp 2043w Firmware | All | All | All | All |
| Operating System | Phoenixcontact | Btp 2043w Firmware | All | All | All | All |
| Hardware | Phoenixcontact | Btp 2070w | - | All | All | All |
| Hardware | Phoenixcontact | Btp 2070w | - | All | All | All |
| Operating System | Phoenixcontact | Btp 2070w Firmware | All | All | All | All |
| Operating System | Phoenixcontact | Btp 2070w Firmware | All | All | All | All |
| Hardware | Phoenixcontact | Btp 2102w | - | All | All | All |
| Hardware | Phoenixcontact | Btp 2102w | - | All | All | All |
| Operating System | Phoenixcontact | Btp 2102w Firmware | All | All | All | All |
| Operating System | Phoenixcontact | Btp 2102w Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHOENIX CONTACT: BTP Touch Panels uncontrolled resource consumption — English (USA) | CONFIRM | cert.vde.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This vulnerability was discovered by Richard Thomas and Tom Chothia of University of Birmingham.
Legacy QID Mappings
- 591326 Phoenix Contact BTP Touch Panels uncontrolled resource consumption Vulnerability (VDE-2020-047)