Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to cause a denial of service on the PLC's network communication module. A successful attack stops all network communication. To restore the network connectivity the device needs to be restarted. The automation task is not affected.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HPhoenixcontact Ilc1x0
HWPhoenixcontactall versionsPhoenixcontact Ilc1x0 Firmware
OSPhoenixcontactall versionsPhoenixcontact Ilc1x1
HWPhoenixcontactall versionsPhoenixcontact Ilc1x1 Firmware
OSPhoenixcontactall versions
Related vulnerabilities
Phoenix Contact: nieuprawniony zdalny dostęp do urządzeń linii klasycznej
Phoenix Contact AXC: nieautoryzowane wgranie złośliwego kodu do sterownika PLC
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthen...
RCE jako root w sterownikach ładowania Phoenix Contact CHARX SEC-3x00
RCE i eskalacja uprawnień w Phoenix Contact CHARX SEC — brak walidacji danych wejściowych