Remote Command Execution Vulnerability in Phoenix Contact ProConOs and MultiProg
CVE-2014-9195

Currently unrated

Key Information:

Vendor
CVE Published:
17 January 2015

Badges

👾 Exploit Exists🟡 Public PoC🟣 EPSS 86%

What is CVE-2014-9195?

A vulnerability exists in Phoenix Contact's ProConOs and MultiProg that allows remote attackers to execute arbitrary commands. The lack of authentication in these products means that any attacker can send specially crafted protocol-compliant traffic to exploit this flaw, potentially leading to unauthorized access and control over the affected systems. This issue emphasizes the importance of implementing robust authentication measures in critical system components.

Affected Version(s)

MultiProg All versions

ProConOs All versions

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

86% chance of being exploited in the next 30 days.

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.