Back to Database
Status published
High
CVE-2020-12499
PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier: Improper path sanitation vulnerability.
Vulnerability Description
In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12499
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This vulnerability was discovered and reported by Amir Preminger of Claroty.
- PHOENIX CONTACT reported the vulnerability to CERT@VDE.
More from PHOENIX CONTACT
View All →CVE-2025-41668
Phoenix Contact: File access due to the replacement of a critical file used by the service security-profile
High
8.8
CVE-2025-41667
Phoenix Contact: File access due to the replacement of a critical file used by the arp-preinit script
High
8.8
CVE-2025-41666
Phoenix Contact: File access due to the replacement of a critical file used by the watchdog
High
8.8
CVE-2025-41665
Phoenix Contact: DoS of the PLC due to incorrect default permissions possible
Medium
6.5
CVE-2024-7734
Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.
Medium
5.3
Affected Vendor
PHOENIX CONTACT
View all reports →Affected Software
PLCnext Engineer
Vulnerable Versions:
unspecified
Timeline
Official Publish:
July 21st, 2020
Last Modified:
September 17th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H