Skip to main content

Access to Critical Private Variable via Public Method

CVE-2016-8380

Severity High
Score 7.3/10

Summary

The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • LOW

CWE-767 - Access to Critical Private Variable via Public Method

The software defines a public method that reads or modifies a private variable.

References

Advisory Timeline

  • Published