Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21247 Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.
Fixes

Solution

With the next version of Automation Worx Software Suite additional plausibility checks for archive content will be implemented.


Workaround

Temporary Fix / Mitigation We strongly recommend customers to exchange project files only using secure file exchange services. Project files should not be exchanged via unencrypted email. In addition, we recommend exchanging or storing project files together with a checksum to ensure their integrity.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T18:09:20.367Z

Reserved: 2021-06-10T00:00:00

Link: CVE-2021-34597

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-04T10:15:07.893

Modified: 2024-11-21T06:10:47.123

Link: CVE-2021-34597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.