Buffer Overflow in PHOENIX CONTACT Automationworx Software Suite
Description
A heap buffer overflow in PHOENIX CONTACT Automationworx Software Suite up to 1.89 allows attackers to compromise workstation availability, integrity, or confidentiality via manipulated BCP files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A heap buffer overflow in PHOENIX CONTACT Automationworx Software Suite up to 1.89 allows attackers to compromise workstation availability, integrity, or confidentiality via manipulated BCP files.
Vulnerability
In PHOENIX CONTACT Automationworx Software Suite versions up to 1.89, insufficient validation of input data in PC Worx or Config+ files (BCP format) can lead to a heap buffer overflow and read access violation. The vulnerability is triggered when parsing specially crafted .bcp files [1].
Exploitation
An attacker must first obtain an original bus configuration file (.bcp) and manipulate its data. The attacker then needs to replace the original file on the application programming workstation with the manipulated one. No authentication is required beyond file access, but physical or remote file system access to the workstation is necessary [1].
Impact
Successful exploitation could compromise the availability, integrity, or confidentiality of the application programming workstation. An attacker may cause denial of service, data corruption, or information disclosure [1].
Mitigation
As of the latest update, no patch is indicated. Users should restrict access to .bcp files and ensure they are obtained from trusted sources. PHOENIX CONTACT recommends validating file integrity before loading [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: <= 1.89
- PHOENIX CONTACT/Config+v5Range: 0
- Range: 0
- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.