« Volver al listado

CVE-2021-34597

Estado: ModificadaAlta (7.8)—

Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-34597",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "Phoenix Contact",
          "product": "PC Worx",
          "versions": [
            {
              "status": "affected",
              "version": "PC Worx",
              "versionType": "custom",
              "lessThanOrEqual": "1.88"
            },
            {
              "status": "affected",
              "version": "PC Worx-Express",
              "versionType": "custom",
              "lessThanOrEqual": "1.88"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-04T10:15:07.893",
  "references": [
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2021-052/",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2021-052/",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de comprobación de entrada inapropiada en PC Worx Automation Suite de Phoenix Contact versiones hasta 1.88, podría permitir a un atacante con un archivo de proyecto manipulado desempaquetar archivos arbitrarios fuera del directorio del proyecto seleccionado"
    }
  ],
  "lastModified": "2026-06-17T03:56:12.543",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:phoenixcontact:pc_worx:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E3BC487-A4B3-4ACA-8E5B-9E6E20378BF2",
              "versionEndIncluding": "1.88"
            },
            {
              "criteria": "cpe:2.3:a:phoenixcontact:pc_worx_express:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02821C93-7E26-4596-9727-0BD71DDF5E93",
              "versionEndIncluding": "1.88"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}