7.5
CVE-2014-9195
- EPSS 80.69%
- Veröffentlicht 17.01.2015 02:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical Function
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact-software ≫ Multiprog Version 5.0
Phoenixcontact-software ≫ Multiprog Version 5.0 SwEdition express
Phoenixcontact-software ≫ Proconos Eclr SwEdition single_chip
Phoenixcontact-software ≫ Proconos Eclr SwEdition softplc
Phoenixcontact-software ≫ Proconos Eclr SwEdition visual_studio
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 80.69% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
| DHS.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://ics-cert.us-cert.gov/advisories/ICSA-15-013-03
https://www.exploit-db.com/exploits/37066/
https://www.cisa.gov/news-events/ics-advisories/icsa-15-013-03