Phoenix Contact: PC Worx/-Express prone to improper input validation vulnerability
Description
PC Worx Automation Suite up to 1.88 allows arbitrary file unpack via a manipulated project file, enabling potential workstation compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
PC Worx Automation Suite up to 1.88 allows arbitrary file unpack via a manipulated project file, enabling potential workstation compromise.
Vulnerability
PC Worx Automation Suite (including PC Worx and PC Worx Express) versions up to 1.88 contain an improper input validation vulnerability in the handling of project files. An attacker can craft a project file that exploits a path traversal (zip slip) weakness to unpack files outside the intended project directory. [1]
Exploitation
An attacker with the ability to deliver a manipulated project file to a user of PC Worx Automation Suite can exploit this vulnerability. The user must load the malicious project file into the software. No additional privileges are required beyond access to the software interface. [1]
Impact
Successful exploitation could allow an attacker to write arbitrary files to arbitrary locations on the workstation where the software is running. This could lead to compromise of availability, integrity, or confidentiality of the programming workstation. Note: Automated systems in operation programmed with these products are not affected. [1]
Mitigation
Phoenix Contact has released a fix in version 1.89 of PC Worx Automation Suite. Users should update to the latest version. No workarounds are provided. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.88
- Range: PC Worx
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- cert.vde.com/en/advisories/VDE-2021-052/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.