Zurück zur Übersicht

PHOENIX CONTACT: BTP Touch Panels uncontrolled resource consumption

VDE-2020-047
Last update
14.05.2025 14:28
Published at
02.12.2020 10:00
Vendor(s)
Phoenix Contact GmbH & Co. KG
External ID
VDE-2020-047
CSAF Document

Summary

Uncontrolled Resource Consumption can be exploited to cause the HMI to become unresponsive and not accurately update the display content (Denial of Service).

Impact

When the HMI is subjected to i.e. a rapid flood of ICMP ping packets, the HMI stops responding to user input and the running program provides no visual changes. Once the attack stops, the HMI will return to normal functionality.

Affected Product(s)

Model no. Product name Affected versions
1050387 BTP 2043W vers:all/*
1046666 BTP 2070W vers:all/*
1046667 BTP 2102W vers:all/*

Vulnerabilities

Expand / Collapse all

Published
22.09.2025 14:57
Weakness
Uncontrolled Resource Consumption (CWE-400)
Summary

Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).

References

Mitigation

Mitigation Phoenix Contact recommends operating network-capable devices in closed networks orprotected with a suitable firewall. For detailed information on the recommendations for measuresto protect network-capable devices, please refer to the Phoenix Contact application note: Measures to protect network-capable devices with Ethernet connection

Revision History

Version Date Summary
1 02.12.2020 10:00 Initial revision.
2 14.05.2025 14:28 Fix: removed ia, added distribution