CVE-2014-9195 describes an authentication bypass vulnerability in Phoenix Contact ProConOs and MultiProg software, allowing remote attackers to execute arbitrary commands. This critical flaw carries a CVSS score of 7.5, indicating a high severity due to its network-based attack vector, low complexity, and potential for complete compromise (confidentiality, integrity, availability). While not listed in CISA's KEV catalog, exploit intelligence shows available Metasploit modules and an ExploitDB script, confirming its exploitability and suggesting it has garnered some community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:a:phoenixcontact-software:multiprog:5.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:phoenixcontact-software:multiprog:5.0:*:*:*:express:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:phoenixcontact-software:multiprog:5.0:*:*:*:pro\+:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:phoenixcontact-software:proconos_eclr:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:phoenixcontact-software:proconos_eclr:*:*:*:*:single_chip:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.