VYPR

PC Worx Automation Suite

by Phoenixcontact

CVEs (3)

  • CVE-2020-12497Jul 1, 2020
    risk 0.01cvss epss 0.08

    PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

  • CVE-2021-34597Nov 4, 2021
    risk 0.00cvss epss 0.00

    Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.

  • CVE-2020-12498Jul 1, 2020
    risk 0.00cvss epss 0.01

    mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.