Impact
This vulnerability is a classic SQL injection flaw that can be exploited through an authenticated web interface endpoint on Phoenix Contact controllers. The flaw allows an attacker with low‑privilege credentials to inject arbitrary SQL into a SQLite database used solely for storing notification messages. The result is that the attacker can read, modify, or delete notification data, which could mislead system operators or disrupt notification flow but does not compromise other device functions or data.
Affected Systems
The vulnerability affects a range of Phoenix Contact industrial controllers and edge devices, including models such as AXC F 1152, AXC F 1252, AXC F 2000 EA, AXC F 2152, AXC F 3152, BPC 9102S, BPC 9202S, Catan C1, EPC 1502, EPC 1522, RFC 4072R, RFC 4072S, VL3 UPC 2440 EDGE, VPLCNext Control 1000, 2000, 3000, and 500. No specific firmware revision numbers are listed, so all currently installed firmware versions of these devices are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium risk, and the EPSS score is not available, suggesting limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed large‑scale attacks. Exploitation requires valid credentials, but low‑privilege users may exist by default or through mis‑management. Until a vendor fix is issued, the primary attack surface is the web interface, which should be isolated to trusted networks or secured using multi‑factor authentication to reduce risk.
OpenCVE Enrichment