On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2020-12-17T22:43:14.320752Z

Updated: 2024-09-16T22:10:20.898Z

Reserved: 2020-04-30T00:00:00

Link: CVE-2020-12517

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-17T23:15:12.873

Modified: 2020-12-21T17:07:29.057

Link: CVE-2020-12517

cve-icon Redhat

No data.