Phoenix Contact: PC Worx/-Express prone to improper input validation vulnerability
Vulnerability Description
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-34597
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- The vulnerability was discovered by Jake Baines of Dragos Inc. We kindly appreciate the coordinated disclosure of these vulnerabilities by the finder.
- PHOENIX CONTACT thanks CERT@VDE for the coordination and support with this publication.
More from Phoenix Contact
View All →Affected Vendor
Phoenix Contact
View all reports →