PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by default for web-based services on the device. Impersonation, man-in-the-middle, or passive decryption attacks are possible if the generic certificate is not replaced by a device-specific certificate during installation.

Project Subscriptions

Vendors Products
Phoenixcontact Subscribe
Tc Cloud Client 1002-4g Subscribe
Tc Cloud Client 1002-4g Firmware Subscribe
Tc Cloud Client 1002-txtx Subscribe
Tc Cloud Client 1002-txtx Firmware Subscribe
Tc Router 2002t-3g Subscribe
Tc Router 2002t-3g Firmware Subscribe
Tc Router 3002t-4g Subscribe
Tc Router 3002t-4g Att Subscribe
Tc Router 3002t-4g Att Firmware Subscribe
Tc Router 3002t-4g Firmware Subscribe
Tc Router 3002t-4g Vzw Subscribe
Tc Router 3002t-4g Vzw Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-30255 PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by default for web-based services on the device. Impersonation, man-in-the-middle, or passive decryption attacks are possible if the generic certificate is not replaced by a device-specific certificate during installation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T10:26:16.091Z

Reserved: 2020-02-27T00:00:00

Link: CVE-2020-9435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-12T14:15:21.707

Modified: 2024-11-21T05:40:38.197

Link: CVE-2020-9435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses