SQL injection
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Phoenix Contact · AXC F 1152Phoenix Contact · AXC F 1252Phoenix Contact · AXC F 2000 EAPhoenix Contact · AXC F 2152Phoenix Contact · AXC F 3152Phoenix Contact · BPC 9102SPhoenix Contact · BPC 9202SPhoenix Contact · Catan C1Phoenix Contact · EPC 1502Phoenix Contact · EPC 1522Phoenix Contact · RFC 4072RPhoenix Contact · RFC 4072SPhoenix Contact · VL3 UPC 2440 EDGEPhoenix Contact · VPLCNEXT CONTROL 1000Phoenix Contact · VPLCNEXT CONTROL 2000Phoenix Contact · VPLCNEXT CONTROL 3000Phoenix Contact · VPLCNEXT CONTROL 500