QID 590969

Date Published: 2022-08-05

QID 590969: Phoenix Contact Classic Line Controllers Vulnerability (ICSA-22-172-03)

AFFECTED PRODUCTS
The following versions of the classic line industrial controllers, are affected:
ILC 1x0 All variants
ILC 1x1 All variants
ILC 1x1 GSM/GPRS: Article number 2700977
ILC 3xx All variants
AXC 1050: Article number 2700988
AXC 1050 XC: Article number 2701295
AXC 3050: Article number 2700989
RFC 480S PN 4TX: Article number 2404577
RFC 470 PN 3TX: Article number 2916600
RFC 470S PN 3TX: Article number 2916794
RFC 460R PN 3TX: Article number 2700784
RFC 460R PN 3TX-S: Article number 1096407
RFC 430 ETH-IB: Article number 2730190
RFC 450 ETH-IB: Article number 2730200
PC WORX SRT: Article number 2701680
PC WORX RT BASIC: Article number 2700291
FC 350 PCI ETH: Article number 2730844

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow an attacker to upload logic with arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-172-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590969

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-172-03 URL Logo www.us-cert.gov/ics/advisories/ICSA-22-172-03