Severity
Medium
Analysis Summary
A manipulated PC Worx or Config+ project file could lead to arbitrary code execution due to insufficient input data validation.
Impact
Improper Input Validation
Affected Vendors
Phoenix Contact
Affected Products
- PC Worx Versions 1.86 and prior
- PC Worx Express Versions 1.86 and prior
- Config+ Versions 1.86 and prior
Remediation
Phoenix Contact strongly recommends users exchange project files using only secure file exchange services, and that project files should not be exchanged via unencrypted email.