Description
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by default for web-based services on the device. Impersonation, man-in-the-middle, or passive decryption attacks are possible if the generic certificate is not replaced by a device-specific certificate during installation.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-30255 | PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by default for web-based services on the device. Impersonation, man-in-the-middle, or passive decryption attacks are possible if the generic certificate is not replaced by a device-specific certificate during installation. |
References
History
No history.
Subscriptions
Phoenixcontact
Subscribe
Tc Cloud Client 1002-4g
Subscribe
Tc Cloud Client 1002-4g Firmware
Subscribe
Tc Cloud Client 1002-txtx
Subscribe
Tc Cloud Client 1002-txtx Firmware
Subscribe
Tc Router 2002t-3g
Subscribe
Tc Router 2002t-3g Firmware
Subscribe
Tc Router 3002t-4g
Subscribe
Tc Router 3002t-4g Att
Subscribe
Tc Router 3002t-4g Att Firmware
Subscribe
Tc Router 3002t-4g Firmware
Subscribe
Tc Router 3002t-4g Vzw
Subscribe
Tc Router 3002t-4g Vzw Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:26:16.091Z
Reserved: 2020-02-27T00:00:00.000Z
Link: CVE-2020-9435
No data.
Status : Modified
Published: 2020-03-12T14:15:21.707
Modified: 2024-11-21T05:40:38.197
Link: CVE-2020-9435
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD