← Vulnerability feed

Vulnerability record · CVE-2019-12870 · published 24 June 2019

CVE-2019-12870: Phoenixcontact automationworx software suite vulnerability

Phoenixcontact · Automationworx Software Suite

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized Pointer and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

8.8 CVSS 3.0 High EPSS 3.7% · top 10.6% CWE-824 · CWE-824
8.8CVSS 3.0 base score, v2 6.8
3.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized Pointer and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12870 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46141Phoenixcontact automationworx software suite incorrect permission assignment vulnerabilityIncorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthen…EPSS 0.88%8.8CVE-2019-12869Phoenixcontact automationworx software suite out-of-bounds read vulnerabilityAn issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Con…EPSS 3.8%8.8CVE-2019-12871Phoenixcontact automationworx software suite use after free vulnerabilityAn issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Con…EPSS 3.7%7.8CVE-2022-3737Phoenixcontact automationworx software suite out-of-bounds read vulnerabilityIn PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of in…EPSS 0.21%7.8CVE-2022-3461Phoenixcontact automationworx software suite memory buffer overflow vulnerabilityIn PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a r…EPSS 0.21%7.5CVE-2023-46143Phoenixcontact automationworx software suite download of code without integrity check vulnerabilityDownload of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some …EPSS 0.33%7.8CVE-2022-21971Windows Runtime use-after-free leads to remote code executionCVE-2022-21971 is a remote code execution flaw in the Windows Runtime component of supported Windows 10, Windows 11 and Windows Server builds. The CV…KEVEPSS 54%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed

Source: NIST National Vulnerability Database (record CVE-2019-12870), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.