Phoenix Contact Automation Worx <= 1.87: out-of-bounds read remote code execution
Description
Out-of-bounds read in PC Worx MWE file parsing enables arbitrary code execution via manipulated projects on Phoenix Contact Automationworx.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Out-of-bounds read in PC Worx MWE file parsing enables arbitrary code execution via manipulated projects on Phoenix Contact Automationworx.
Vulnerability
A memory-corruption vulnerability exists in the MWE file parsing logic of Phoenix Contact PC Worx and PC Worx Express versions 1.87 and earlier. The flaw is an out-of-bounds read caused by insufficient validation of user-supplied data when a specially crafted project file is opened. Affected products are part of the Automationworx suite [1].
Exploitation
To exploit this issue, an attacker must convince a target user to open a malicious MWE file (e.g., by visiting a compromised page or opening a booby-trapped project). No authentication is required, but user interaction is necessary. The vulnerability is reachable locally; the CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [1].
Impact
Successful exploitation allows an attacker to execute arbitrary code in the context of the current process. This could lead to full compromise of the workstation, including disclosure, modification, or destruction of project data and potentially affecting industrial control system integrity [1].
Mitigation
The vendor has not released a fixed version in the available references; users should limit opening MWE files from untrusted sources. The advisory [1] provides no patch details. For the latest updates, consult Phoenix Contact's security portal. No KEV listing is reported at this time.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: <=1.87
- Range: <=1.87
- Range: unspecified
- Phoenix Contact/Automation Worx Expressv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- cert.vde.com/de-de/advisories/vde-2020-023mitrex_refsource_CONFIRM
- www.zerodayinitiative.com/advisories/ZDI-20-826/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.