CVE-2020-12519

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CERTVDECNA
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
phoenixcontactplcnext_firmware
𝑥
< 2021.0
phoenixcontactplcnext_firmware
𝑥
< 2021.0
phoenixcontactplcnext_firmware
𝑥
< 2021.0
phoenixcontactplcnext_firmware
𝑥
< 2021.0
phoenixcontactplcnext_firmware
𝑥
< 2021.0
phoenixcontactplcnext_firmware
𝑥
< 2021.0
𝑥
= Vulnerable software versions