CVE-2019-12869
Description
An out-of-bounds read in Phoenix Contact Automationworx BCP file parsing allows information disclosure and potential remote code execution via a manipulated project file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read in Phoenix Contact Automationworx BCP file parsing allows information disclosure and potential remote code execution via a manipulated project file.
Vulnerability
The vulnerability exists in the parsing of BCP files within Phoenix Contact Automationworx products, specifically PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. The issue results from a lack of proper validation of user-supplied data, which can cause a read past the end of an allocated buffer [1].
Exploitation
An attacker must first obtain an original PC Worx or Config+ project file, then manipulate it to trigger the out-of-bounds read. The attacker then needs to exchange the original file with the manipulated one on the application programming workstation. User interaction is required: the target must open the malicious file or visit a malicious page [1].
Impact
Successful exploitation leads to information disclosure via the out-of-bounds read. The advisory notes that an attacker can leverage this vulnerability in conjunction with other vulnerabilities to execute code in the context of the current process [1]. The CVSS score is 3.3 (low severity) for the information disclosure aspect.
Mitigation
As of the publication date (2019-06-24), no patch is mentioned in the available references. Users should ensure they only open project files from trusted sources and verify file integrity. The vendor may have released updates after the advisory; consult Phoenix Contact's security advisories for the latest fixed versions.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- PHOENIX CONTACT/PC Worxdescription
- Range: <=1.86
- Range: <=1.86
- Range: <=1.86
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.vde.com/en-us/advisories/vde-2019-014mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-19-579/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.