CVE-2016-8380
05.04.2018, 16:29
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.Enginsight
Vendor | Product | Version |
---|---|---|
phoenixcontact | ilc_plcs_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-767 - Access to Critical Private Variable via Public MethodThe software defines a public method that reads or modifies a private variable.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.