Out-of-bounds Read in PHOENIX CONTACT Automationworx Software Suite
Description
A memory read beyond bounds vulnerability in PHOENIX CONTACT Automationworx Software Suite up to 1.89 allows attackers to compromise workstation confidentiality, integrity, or availability via a crafted BCP file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory read beyond bounds vulnerability in PHOENIX CONTACT Automationworx Software Suite up to 1.89 allows attackers to compromise workstation confidentiality, integrity, or availability via a crafted BCP file.
Vulnerability
In PHOENIX CONTACT Automationworx Software Suite versions up to 1.89, insufficient input validation when parsing bus configuration files (*.bcp) can lead to memory reads beyond the intended scope, including heap buffer overflows, release of unallocated memory, or read access violations [1].
Exploitation
An attacker must gain access to an original *.bcp file, manipulate its data, and then replace the original file on the application programming workstation. The workstation user must subsequently open the manipulated file in the software to trigger the vulnerability [1].
Impact
Successful exploitation can compromise the availability, integrity, or confidentiality of the application programming workstation. Potential outcomes include information disclosure, denial of service, or arbitrary code execution depending on the specific memory corruption [1].
Mitigation
Update to Automationworx Software Suite version 1.90 or later, which contains the fix. As a workaround, avoid opening untrusted BCP files from unverified sources [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: <=1.89
- PHOENIX CONTACT/Config+v5Range: 0
- Range: 0
- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.