CVE-2020-12518
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.
Affected (1)
Products: Phoenixcontact: Plcnext Firmware
Configuration A
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc F 1152 | All versions |
Configuration B
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc F 2152 | All versions |
Configuration C
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc F 3152 | All versions |
Configuration D
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Rfc 4072s | All versions |
Configuration E
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc F 2152 Starterkit | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2021.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Plcnext Technology Starterkit | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.