9
CVE-2020-12517
- EPSS 0.61%
- Veröffentlicht 17.12.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:51
- Quelle info@cert.vde.com
- Teams Watchlist Login
- Unerledigt Login
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact ≫ Plcnext Firmware SwEditionlong_term_support Version < 2021.0
Phoenixcontact ≫ Plcnext Firmware SwEditionlong_term_support Version < 2021.0
Phoenixcontact ≫ Plcnext Firmware SwEditionlong_term_support Version < 2021.0
Phoenixcontact ≫ Plcnext Firmware SwEditionlong_term_support Version < 2021.0
Phoenixcontact ≫ Plcnext Firmware SwEditionlong_term_support Version < 2021.0
Phoenixcontact ≫ Plcnext Firmware SwEditionlong_term_support Version < 2021.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.61% | 0.688 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
info@cert.vde.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.