HIGH
Out-of-bounds Read in PHOENIX CONTACT Automationworx Software Suite
Published Nov 15, 2022
7.8
HIGHCVSS 3.1
EPSS 0.21%
Description
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
Affected products
-
Affected
- ≥ 0, ≤ 1.89
-
Affected
- ≥ 0, ≤ 1.89
-
Affected
- ≥ 0, ≤ 1.89
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Phoenix Contact | Config+ | unaffected | Affected
|
| Phoenix Contact | PC Worx | unaffected | Affected
|
| Phoenix Contact | PC Worx Express | unaffected | Affected
|
- 1.89
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to Automation Worx Software Suite > 1.89
Weaknesses (1)
References (2)
- https://cert.vde.com/en/advisories/VDE-2022-048/ Third Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43093 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-048/ | Third Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43093 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERTVDE
Published Nov 15, 2022
Updated Apr 28, 2025
Reserved Oct 28, 2022
Link CVE-2022-3737
CISA Vulnrichment
Updated Apr 28, 2025
Red Hat
No data
GitHub
No data