CVE-2020-12499: Phoenixcontact Plcnext Engineer

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.

Affected products

Published 2020-07-21. Last modified 2026-06-17.