QID 591322

Date Published: 2023-04-03

QID 591322: Phoenix Contact Classic Line industrial controllers Remote configuration using unauthenticated communication protocols Vulnerability (VDE-2019-015)

AFFECTED PRODUCTS
AXC 1050: all versions
AXC 1050 XC: all versions
AXC 3050: all versions
FC 350 PCI ETH: all versions
ILC1x1: all versions
ILC1x0: all versions
ILC 1x1 GSM/GPRS: all versions
RFC 430 ETH-IB: all versions
RFC 450 ETH-IB: all versions
RFC 460R PN 3TX: all versions
RFC 460R PN 3TX-S: all versions
RFC 470 PN 3TX: all versions
RFC 470S PN 3TX: all versions
RFC 480S PN 4TX: all versions

QID Detection Logic:
This QID checks for the Vulnerable version of Phoenix Contact Classic Line industrial controllers using passive scanning

If the Phoenix Contact Classic Line industrial controllers (ILC1x0 and ILC1x1 product families as well as the AXIOLINE controllers AXC1050 and AXC3050) are used in an unprotected open network, an unauthorized attacker can change or download the device configuration, start or stop services, update or modify the firmware or shutdown the device.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section VDE-2019-015 for affected packages and patching details.

    CVEs related to QID 591322

    Software Advisories
    Advisory ID Software Component Link
    © CVE.report 2026 |

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report