CVE-2019-16675
Last modified
CVE-2019-16675 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. EPSS estimates a 3.31% chance of exploitation in the next 30 days.
Description
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phoenixcontact | Config\+ | <= 1.86 |
| Phoenixcontact | Pc Worx | <= 1.86 |
| Phoenixcontact | Pc Worx Express | <= 1.86 |
References
- https://cert.vde.com/en-us/advisoriesThird Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-302-01Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-19-922/Third Party Advisory, VDB Entry
- https://cert.vde.com/en-us/advisoriesThird Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-302-01Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-19-922/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-16675?
How severe is CVE-2019-16675?
How do I fix CVE-2019-16675?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1667A vulnerability in the Graphite interface of Cisco HyperFlex…3.3
- CVE-2019-16670An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Bui…9.8
- CVE-2019-16671An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Bui…6.5
- CVE-2019-16672An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Bui…9.8
- CVE-2019-16673An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Bui…6.5
- CVE-2019-16674An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Bui…9.8
- CVE-2019-16676Plataformatec Simple Form has Incorrect Access Control in fi…9.8
- CVE-2019-16677An issue was discovered in idreamsoft iCMS V7.0. admincp.php…6.5
- CVE-2019-16678admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resu…6.5
- CVE-2019-16679Gila CMS before 1.11.1 allows admin/fm/?f=../ directory trav…4.9
- CVE-2019-1668A vulnerability in the chat feed feature of Cisco SocialMine…6.1
- CVE-2019-16680An issue was discovered in GNOME file-roller before 3.29.91.…4.3
Are you affected by CVE-2019-16675?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
