VulnerabilityModified
CVE-2020-12524
Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).
HIGH 7.5EPSS 1.08%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- phoenixcontact/btp 2043w firmware · phoenixcontact/btp 2070w firmware · phoenixcontact/btp 2102w firmware
- Source
- info@cert.vde.com
References
- https://cert.vde.com/en-us/advisories/vde-2020-047Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2020-047Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.