peter bassill · operator
$ cve CVE-2019-9201 JSON

CVE-2019-9201

9.8
CRITICAL · CVSS 3.1 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.1% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2019-02-26
Last modified2026-06-17

Affected (16)

VendorProduct
phoenixcontactaxc 1050
phoenixcontactaxc 1050 firmware
phoenixcontactilc 131 eth
phoenixcontactilc 131 eth firmware
phoenixcontactilc 131 eth\/xc
phoenixcontactilc 131 eth\/xc firmware
phoenixcontactilc 151 eth
phoenixcontactilc 151 eth firmware
phoenixcontactilc 151 eth\/xc
phoenixcontactilc 151 eth\/xc firmware
phoenixcontactilc 171 eth 2tx
phoenixcontactilc 171 eth 2tx firmware
phoenixcontactilc 191 eth 2tx
phoenixcontactilc 191 eth 2tx firmware
phoenixcontactilc 191 me\/an
phoenixcontactilc 191 me\/an firmware

References

→ the Explorer  ·  watch your stack  ·  NVD