QID 590940

Date Published: 2022-07-22

QID 590940: PHOENIX CONTACT PLCnext Control devices Vulnerability (VDE-2021-029)

Affected Products
AXC F 1152 version prior to 2021.0.5 LTS
AXC F 2152 version prior to 2021.0.5 LTS
AXC F 3152 version prior to 2021.0.5 LTS
RFC 4072S version prior to 2021.0.5 LTS
AXC F 2152 Starterkit version prior to2021.0.5 LTS
PLCnext Technology Starterkit version prior to 2021.0 5 LTS

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An attacker could potentially script this request and create a denial of service attack condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section VDE-2021-029 for affected packages and patching details.

    CVEs related to QID 590940

    Software Advisories
    Advisory ID Software Component Link
    VDE-2021-029 URL Logo dam-mdc.phoenixcontact.com/asset/156443151564/cf2d9a089f16af45a68d7fb8db7968c8/Security_Advisory-CVE-2021-34570.pdf?_gl=1*hs2c0q*_ga*MTYwNDQyMzQ3My4xNjMyMTk5MTY3*_ga_6B4SS2SVV4*MTYzNTQxNjY1My4xLjAuMTYzNTQxNjY1My4w