CVE-2022-31801
Published Jun 21, 2022An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
Vendor/product archive
2 CVEs tagged to phoenixcontact-software / proconos_eclr — 2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.