Back

HIGH

Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical Function

Published Jan 17, 2015

Description

Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.

Affected products

Remediation

Vendor solution

Phoenix Contact Software designed the applications and protocols without authentication mechanisms. It is the understanding of Phoenix Contact Software that vendors using the application software and its protocol would incorporate its own authentication mechanism in its final product. Phoenix Contact Software is considering adding authentication software into future versions of its application software and its protocol.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jan 17, 2015
Updated Sep 5, 2025
Reserved Dec 2, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a