{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "tracking": {
            "generator": {
                "date": "2025-04-09T07:58:21.647Z",
                "engine": {
                    "version": "2.5.22",
                    "name": "Secvisogram"
                }
            },
            "current_release_date": "2025-05-22T13:03:10.000Z",
            "id": "VDE-2022-026",
            "initial_release_date": "2022-06-21T05:16:00.000Z",
            "version": "2",
            "status": "final",
            "revision_history": [
                {
                    "number": "1",
                    "date": "2022-06-21T05:16:00.000Z",
                    "summary": "Initial revision."
                },
                {
                    "number": "2",
                    "summary": "Fix: added distribution, quotation mark",
                    "date": "2025-05-22T13:03:10.000Z"
                }
            ],
            "aliases": [
                "VDE-2022-026"
            ]
        },
        "title": "PHOENIX CONTACT: Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering tool",
        "lang": "en-GB",
        "acknowledgments": [
            {
                "organization": "CERT@VDE",
                "summary": "coordination"
            },
            {
                "organization": "Forescout",
                "summary": "reporting."
            }
        ],
        "notes": [
            {
                "category": "summary",
                "text": "ProConOS/ProConOS eCLR insufficiently verifies uploaded data.",
                "title": "Summary"
            },
            {
                "category": "description",
                "text": "The identified vulnerability allows attackers uploading logic with arbitrary malicious code oncehaving access to the communication to products that are utilizing ProConOS/ProConOS eCLR.Attackers must have network or physical controller access to exploit this vulnerability. Thisvulnerability affects all versions of ProConOS/ProConOS eCLR and MULTIPROG from PhoenixContact Software (formerly KW-Software).",
                "title": "Impact"
            },
            {
                "category": "description",
                "text": "Manufacturers using ProConOS/ProConOS eCLR in their automation devices are advised tocheck their implementation and may publish an advisory according to their product.\nUsers of automation devices utilizing ProConOS/ProConOS eCLR in their automation systemsmay check if their application requires additional security measures like an adequate defense–in-depth networking architecture, the use of virtual private networks (VPNs) for remote access,as well as the use of firewalls for network segmentation or controller isolation.\nUsers should check their manufacturers security advisories for more adequate informationaccording to their dedicated device.\nUsers should ensure that the logic is always transferred or stored in protected environments.This is valid for data in transmission as well as data in rest. Connections between theEngineering Tools and the controller must always be in a locally protected environment orprotected by VPN for remote access. Project data shouldn't send as a file via e-mail or othertransfer mechanisms without additional integrity and authenticity checks.Project data should save in protected environments only.\nGeneric information and recommendations for security measures to protect network-capabledevices can be found in the application note.",
                "title": "Mitigation"
            }
        ],
        "publisher": {
            "contact_details": "psirt@phoenixcontact.com",
            "category": "vendor",
            "name": "Phoenix Contact GmbH & Co. KG",
            "namespace": "https://phoenixcontact.com/psirt"
        },
        "references": [
            {
                "summary": "PHOENIX CONTACT PSIRT ",
                "url": "https://phoenixcontact.com/psirt",
                "category": "external"
            },
            {
                "summary": "CERT@VDE Security Advisories for PHOENIX CONTACT",
                "url": "https://certvde.com/en/advisories/vendor/phoenixcontact/",
                "category": "external"
            },
            {
                "summary": "VDE-2022-026: PHOENIX CONTACT: Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering tool - HTML",
                "url": "https://certvde.com/en/advisories/VDE-2022-026/",
                "category": "self"
            },
            {
                "url": "https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-026.json",
                "summary": "VDE-2022-026: PHOENIX CONTACT: Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering tool - CSAF",
                "category": "self"
            }
        ],
        "distribution": {
            "tlp": {
                "label": "WHITE",
                "url": "https://www.first.org/tlp/"
            }
        }
    },
    "product_tree": {
        "branches": [
            {
                "name": "Phoenix Contact",
                "category": "vendor",
                "branches": [
                    {
                        "name": "Software",
                        "category": "product_family",
                        "branches": [
                            {
                                "name": "MULTIPROG",
                                "category": "product_name",
                                "branches": [
                                    {
                                        "name": "vers:all/*",
                                        "category": "product_version_range",
                                        "product": {
                                            "name": "MULTIPROG vers:all/*",
                                            "product_id": "CSAFPID-51001"
                                        }
                                    }
                                ]
                            },
                            {
                                "name": "ProConOS",
                                "category": "product_name",
                                "branches": [
                                    {
                                        "name": "vers:all/*",
                                        "category": "product_version_range",
                                        "product": {
                                            "name": "ProConOS vers:all/*",
                                            "product_id": "CSAFPID-51002"
                                        }
                                    }
                                ]
                            },
                            {
                                "name": "ProConOS eCLR",
                                "category": "product_name",
                                "branches": [
                                    {
                                        "name": "vers:all/*",
                                        "category": "product_version_range",
                                        "product": {
                                            "name": "ProConOS eCLR vers:all/*",
                                            "product_id": "CSAFPID-51003"
                                        }
                                    }
                                ]
                            }
                        ]
                    }
                ]
            }
        ],
        "product_groups": [
            {
                "group_id": "CSAFGID-0001",
                "summary": "Affected Products",
                "product_ids": [
                    "CSAFPID-51001",
                    "CSAFPID-51002",
                    "CSAFPID-51003"
                ]
            }
        ]
    },
    "vulnerabilities": [
        {
            "title": "CVE-2022-31801",
            "cve": "CVE-2022-31801",
            "cwe": {
                "id": "CWE-345",
                "name": "Insufficient Verification of Data Authenticity"
            },
            "notes": [
                {
                    "title": "Vulnerability Description",
                    "category": "description",
                    "text": "An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device."
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-51001",
                    "CSAFPID-51002",
                    "CSAFPID-51003"
                ]
            },
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "Manufacturers using ProConOS/ProConOS eCLR in their automation devices are advised to\ncheck their implementation and may publish an advisory according to their product.\n\nUsers of automation devices utilizing ProConOS/ProConOS eCLR in their automation systems\nmay check if their application requires additional security measures like an adequate defense–\nin-depth networking architecture, the use of virtual private networks (VPNs) for remote access,\nas well as the use of firewalls for network segmentation or controller isolation.\n\nUsers should check their manufacturers security advisories for more adequate information\naccording to their dedicated device.\n\nUsers should ensure that the logic is always transferred or stored in protected environments.\nThis is valid for data in transmission as well as data in rest. Connections between the\nEngineering Tools and the controller must always be in a locally protected environment or\nprotected by VPN for remote access. Project data shouldn't send as a file via e-mail or other\ntransfer mechanisms without additional integrity and authenticity checks.\nProject data should save in protected environments only.\n\nGeneric information and recommendations for security measures to protect network-capable\ndevices can be found in the application note.",
                    "group_ids": [
                        "CSAFGID-0001"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "temporalScore": 9.8,
                        "temporalSeverity": "CRITICAL",
                        "environmentalScore": 9.8,
                        "environmentalSeverity": "CRITICAL",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH"
                    },
                    "products": [
                        "CSAFPID-51001",
                        "CSAFPID-51002",
                        "CSAFPID-51003"
                    ]
                }
            ]
        }
    ]
}