Arbitrary Code Upload and Unauthorized Access Vulnerability in PHOENIX CONTACT MULTIPROG and ProConOS eCLR (SDK)

Arbitrary Code Upload and Unauthorized Access Vulnerability in PHOENIX CONTACT MULTIPROG and ProConOS eCLR (SDK)

CVE-2023-0757 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.

Learn more about our Contact.