Adobe released updates for Flash Player and the ColdFusion platform, which featured bugs that threaten…
Phoenix Contact FL NAT SMx Solution contains a vulnerability (CVE-2019-9744) that allows an unauthorized user to access device settings.
The problem affects the following models: FL NAT SMN 8TX-M (2702443), FL NAT SMN 8TX-M-DMG (2989352), FL NAT SMN 8TX (2989365), and FL NAT SMCS 8TX (2989378). The severity of vulnerability is estimated as 8.8 points in the CVSS v3 scale.
The Phoenix Contact PLCNext AXC F 2152 solution revealed three vulnerabilities (CVE-2018-7559, CVE-2019-10998, CVE-2019-10997).
Using the first, attacker can decrypt the password set on the server.
Vulnerability CVE-2019-10998 allows bypassing device authentication mechanism (for a successful attack, an attacker will need physical access to the device).
By exploiting a third vulnerability, an attacker in “man in the middle” position can cause a malfunction in the PLC. Vulnerabilities affect following products: AXC F 2152-2404267 and AXC F 2152-1046568 (Starterkit).
Read also: About 5.5% of detected vulnerabilities used for implementation real attacks
Currently, no exploitation of the above vulnerabilities has been identified.
Phoenix Contact recommends that you have a firewall.
Source: https://ics-cert.us-cert.gov
Kabatibly.co.in is a domain that tries to force you into clik to its browser notifications…
Reditarcet.co.in is a site that tries to force you into subscribing to its browser notifications…
Everestpeak.top is a domain that tries to trick you into subscribing to its browser notifications…
Firm-jawed.yachts is a domain that tries to trick you into subscribing to its browser notifications…
Anapurnatop.top is a domain that tries to trick you into subscribing to its browser notifications…
Boomira.com is a domain that tries to force you into clik to its browser notifications…
View Comments
The security vulnerabilities are known to us. You will find corresponding information regarding industrial switches Phoenix Contact FL NAT SMx and controllers Phoenix Contact PLCnext AXC F 2152 on the US-Cert website (https://ics-cert.us-cert.gov/advisories/) and on our Phoenix Contact website (https://phoe.co/ProductSecurityIncidentResponseTeam) .
Igor Knezevic
PHOENIX CONTACT GmbH & Co. KG