V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-9195
CVE
HighConfirmedExploit available

Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via proto…

CVSS
7.5
High
EPSS
0.81
p99
Published
2014-01-01
Updated
2014-01-01
Description

Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.

Tags · CWE
CWE-306
CAPEC-12
CAPEC-36
CAPEC-62
CAPEC-166
CAPEC-216
Affected products
Multiprog
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.811 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
37066
exploitdb · https://www.exploit-db.com/exploits/37066
Enterprise
Affected products
ProductVendorStatus
multiprog*Tracked
proconos_eclr*Tracked
Source databases
CVE