CVE-2022-31800

An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
phoenixcontactaxc_1050_firmware
*
phoenixcontactaxc_1050_xc_firmware
*
phoenixcontactaxc_3050_firmware
*
phoenixcontactfc_350_pci_eth_firmware
*
phoenixcontactilc1x0_firmware
*
phoenixcontactilc1x1_firmware
*
phoenixcontactilc_1x1_gsm\/gprs_firmware
*
phoenixcontactilc_3xx_firmware
*
phoenixcontactpc_worx_rt_basic_firmware
*
phoenixcontactpc_worx_srt_firmware
*
phoenixcontactrfc_430_eth-ib_firmware
*
phoenixcontactrfc_450_eth-ib_firmware
*
phoenixcontactrfc_460r_pn_3tx_firmware
*
phoenixcontactrfc_460r_pn_3tx-s_firmware
*
phoenixcontactrfc_470_pn_3tx_firmware
*
phoenixcontactrfc_470s_pn_3tx_firmware
*
phoenixcontactrfc_480s_pn_4tx_firmware
*
𝑥
= Vulnerable software versions