CVE-2020-12521
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
17 dic 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system services or a complete reboot.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
Phoenix Contact · AXC F 1152 (1151412)Phoenix Contact · AXC F 2152 (2404267)Phoenix Contact · AXC F 2152 Starterkit (1046568)Phoenix Contact · AXC F 3152 (1069208)Phoenix Contact · PLCnext Technology Starterkit (1188165)Phoenix Contact · RFC 4072S (1051328¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →