CVE-2021-34570

Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CERTVDECNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
phoenixcontactplcnext_technology_starterkit_firmware
𝑥
< 2021.0.5
phoenixcontactaxc_f_2152_starterkit_firmware
𝑥
< 2021.0.5
phoenixcontactrfc_4072s_firmware
𝑥
< 2021.0.5
phoenixcontactaxc_f_3152_firmware
𝑥
< 2021.0.5
phoenixcontactaxc_f_1152_firmware
𝑥
< 2021.0.5
phoenixcontactaxc_f_2152_firmware
𝑥
< 2021.0.5
𝑥
= Vulnerable software versions