Access to Critical Private Variable via Public Method
CVE-2016-8380
Summary
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- NONE
- LOW
- LOW
CWE-767 - Access to Critical Private Variable via Public Method
The software defines a public method that reads or modifies a private variable.
References
Advisory Timeline
- Published