VulnerabilityModified
CVE-2020-12497
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow.
HIGH 7.8EPSS 14.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 14.67% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-787
- Affected
- phoenixcontact/pc worx · phoenixcontact/pc worx express
- Source
- info@cert.vde.com
References
- https://cert.vde.com/de-de/advisories/vde-2020-023Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-825/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-21-398/Third Party Advisory, VDB Entry
- https://cert.vde.com/de-de/advisories/vde-2020-023Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-825/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-21-398/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.