{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "tracking": {
      "generator": {
        "date": "2025-03-19T11:18:52.367Z",
        "engine": {
          "version": "2.5.21",
          "name": "Secvisogram"
        }
      },
      "current_release_date": "2020-03-27T09:48:00.000Z",
      "id": "VDE-2020-013",
      "initial_release_date": "2020-03-27T09:48:00.000Z",
      "status": "final",
      "version": "1",
      "revision_history": [
        {
          "date": "2020-03-27T09:48:00.000Z",
          "number": "1",
          "summary": "Initial revision."
        }
      ],
      "aliases": [
        "VDE-2020-013"
      ]
    },
    "lang": "en-GB",
    "title": "PHOENIX CONTACT: Local Privilege Escalation in Portico Remote desktop control software",
    "distribution": {
      "tlp": {
        "url": "https://www.first.org/tlp/",
        "label": "WHITE"
      }
    },
    "notes": [
      {
        "title": "Summary",
        "category": "summary",
        "text": "If the software runs as a service, a user with limited access can gain administrator privileges by starting a shell with administrator rights from the Import / Export configuration dialog."
      },
      {
        "title": "Impact",
        "category": "description",
        "text": "A malicious user could use this vulnerability to gain administrator privileges on the Computer running the Portico software."
      },
      {
        "title": "Remediation",
        "category": "description",
        "text": "Phoenix Contact strongly recommends users to upgrade to Portico V3.0.8 or higher which fixes this vulnerability. The current version of Portico is available on the Phoenix Contact website external link.\n\nPhoenix Contact strongly recommends protection measures against unauthorized access for network-compatible devices, solutions and PC-based software. For detailed information please refer to our application note:\n\nMeasures to protect network-compatible devices with communication interfaces, solutions and PC-based software against unauthorized access external link"
      }
    ],
    "publisher": {
      "category": "vendor",
      "name": "Phoenix Contact GmbH & Co. KG",
      "namespace": "https://phoenixcontact.com/psirt",
      "contact_details": "psirt@phoenixcontact.com"
    },
    "references": [
      {
        "summary": "CERT@VDE Security Advisories for PHOENIX CONTACT",
        "url": "https://certvde.com/en/advisories/vendor/phoenixcontact/",
        "category": "external"
      },
      {
        "summary": "VDE-2020-013: PHOENIX CONTACT: Local Privilege Escalation in Portico Remote desktop control software - HTML",
        "url": "https://certvde.com/de/advisories/VDE-2020-013/",
        "category": "self"
      },
      {
        "summary": "VDE-2020-013: PHOENIX CONTACT: Local Privilege Escalation in Portico Remote desktop control software - CSAF",
        "category": "self",
        "url": "https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-013.json"
      }
    ],
    "acknowledgments": [
      {
        "summary": "coordination",
        "organization": "CERT@VDE"
      }
    ]
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "PHOENIX CONTACT",
        "branches": [
          {
            "name": "Software",
            "category": "product_family",
            "branches": [
              {
                "name": "PORTICO SERVER 16 CLIENT",
                "category": "product_name",
                "branches": [
                  {
                    "name": "<=3.0.7",
                    "category": "product_version_range",
                    "product": {
                      "name": "Software PORTICO SERVER 16 CLIENT <=3.0.7",
                      "product_id": "CSAFPID-21001"
                    }
                  },
                  {
                    "name": "V3.0.8",
                    "category": "product_version",
                    "product": {
                      "name": "PORTICO SERVER 16 CLIENT V3.0.8",
                      "product_id": "CSAFPID-22001"
                    }
                  }
                ]
              },
              {
                "category": "product_name",
                "name": "PORTICO SERVER 1 CLIENT",
                "branches": [
                  {
                    "name": "<=3.0.7",
                    "category": "product_version_range",
                    "product": {
                      "name": "Software PORTICO SERVER 1 CLIENT <=3.0.7",
                      "product_id": "CSAFPID-21002"
                    }
                  },
                  {
                    "name": "V3.0.8",
                    "category": "product_version",
                    "product": {
                      "name": "PORTICO SERVER 1 CLIENT V3.0.8",
                      "product_id": "CSAFPID-22002"
                    }
                  }
                ]
              },
              {
                "category": "product_name",
                "name": "PORTICO SERVER 4 CLIENT",
                "branches": [
                  {
                    "name": "<=3.0.7",
                    "category": "product_version_range",
                    "product": {
                      "name": "PORTICO SERVER 4 CLIENT <=3.0.7",
                      "product_id": "CSAFPID-21003"
                    }
                  },
                  {
                    "name": "V3.0.8",
                    "category": "product_version",
                    "product": {
                      "name": "PORTICO SERVER 4 CLIENT V3.0.8",
                      "product_id": "CSAFPID-22003"
                    }
                  }
                ]
              }
            ]
          }
        ]
      }
    ],
    "product_groups": [
      {
        "group_id": "CSAFGID-0001",
        "product_ids": [
          "CSAFPID-21001",
          "CSAFPID-21002",
          "CSAFPID-21003"
        ],
        "summary": "Affected products."
      },
      {
        "group_id": "CSAFGID-0002",
        "product_ids": [
          "CSAFPID-22001",
          "CSAFPID-22002",
          "CSAFPID-22003"
        ],
        "summary": "Fixed products."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-10940",
      "title": "CVE-2020-10940",
      "cwe": {
        "id": "CWE-269",
        "name": "Improper Privilege Management"
      },
      "notes": [
        {
          "title": "Vulnerability Description",
          "text": "Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.",
          "category": "description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-21001",
          "CSAFPID-21002",
          "CSAFPID-21003"
        ],
        "fixed": [
          "CSAFPID-22001",
          "CSAFPID-22002",
          "CSAFPID-22003"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Phoenix Contact strongly recommends users to upgrade to Portico V3.0.8 or higher which fixes this vulnerability. The current version of Portico is available on the Phoenix Contact website external link.\n\nPhoenix Contact strongly recommends protection measures against unauthorized access for network-compatible devices, solutions and PC-based software. For detailed information please refer to our application note:\n\nMeasures to protect network-compatible devices with communication interfaces, solutions and PC-based software against unauthorized access external link",
          "product_ids": [
            "CSAFPID-21001",
            "CSAFPID-21002",
            "CSAFPID-21003"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "temporalScore": 7.8,
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.8,
            "environmentalSeverity": "HIGH",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH"
          },
          "products": [
            "CSAFPID-21001",
            "CSAFPID-21002",
            "CSAFPID-21003"
          ]
        }
      ]
    }
  ]
}