QID 591322
Date Published: 2023-04-03
QID 591322: Phoenix Contact Classic Line industrial controllers Remote configuration using unauthenticated communication protocols Vulnerability (VDE-2019-015)
AFFECTED PRODUCTS
AXC 1050: all versions
AXC 1050 XC: all versions
AXC 3050: all versions
FC 350 PCI ETH: all versions
ILC1x1: all versions
ILC1x0: all versions
ILC 1x1 GSM/GPRS: all versions
RFC 430 ETH-IB: all versions
RFC 450 ETH-IB: all versions
RFC 460R PN 3TX: all versions
RFC 460R PN 3TX-S: all versions
RFC 470 PN 3TX: all versions
RFC 470S PN 3TX: all versions
RFC 480S PN 4TX: all versions
QID Detection Logic:
This QID checks for the Vulnerable version of Phoenix Contact Classic Line industrial controllers using passive scanning
If the Phoenix Contact Classic Line industrial controllers (ILC1x0 and ILC1x1 product families as well as the AXIOLINE controllers AXC1050 and AXC3050) are used in an unprotected open network, an unauthorized attacker can change or download the device configuration, start or stop services, update or modify the firmware or shutdown the device.
Customers are advised to refer to CERT MITIGATIONS section VDE-2019-015 for affected packages and patching details.
CVEs related to QID 591322
| Advisory ID | Software | Component | Link |
|---|