Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
1.0.0 (custom) before 1.9.0
affected
Default status
unaffected
1.0.0 (custom) before 1.9.0
affected
Default status
unaffected
1.0.0 (custom) before 1.9.0
affected
Default status
unaffected
1.0.0 (custom) before 1.9.0
affected
Description
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
1.0.0 (custom) before 1.9.0
1.0.0 (custom) before 1.9.0
1.0.0 (custom) before 1.9.0
1.0.0 (custom) before 1.9.0
Credits
Piotr Ptaszek, Mateusz Wójcik from ZDI
References
phoenixcontact.csaf-tp.certvde.com/...2026/vde-2026-060.json
certvde.com/de/advisories/VDE-2026-060/