CVE-2019-16675: Phoenixcontact Config+
High severity, CVSS 7.8. EPSS: 3.3% chance of exploitation in the next 30 days.
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.
Affected products
- Phoenixcontact Config+: up to and including 1.86
- Phoenixcontact Pc Worx: up to and including 1.86
- Phoenixcontact Pc Worx Express: up to and including 1.86
Published 2019-10-31. Last modified 2026-06-17.