Vulnerabilities in PHOENIX CONTACT

167 results
Vexday analysis

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2022-31800CRITICALInsufficient Verification of Data Vulnerability in PHOENIX CONTACT classic line industrial controllersEPSS 1.5%CVE-2024-25995CRITICALPHOENIX CONTACT: Remote code execution in CHARX SeriesEPSS 1.4%CVE-2026-44098HIGHOS Command Injection in OCPP Agent via charge_box_idEPSS 1.4%CVE-2022-29897CRITICALRemote Code Execution in all versions of various RAD-ISM-900-EN-* devices by PHOENIX CONTACTEPSS 1.3%CVE-2024-28135MEDIUMPHOENIX CONTACT: command injection vulnerability in the API of the CHARX SeriesEPSS 1.3%CVE-2021-33555HIGHA vulnerability may allow remote attackers to read arbitrary files on the server of the WirelessHART-GatewayEPSS 1.2%CVE-2024-26003HIGHPHOENIX CONTACT: DoS of the control agent in CHARX SeriesEPSS 1.2%CVE-2020-12517HIGHPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).EPSS 1.1%CVE-2020-12524HIGHPhoenix Contact BTP Touch Panels uncontrolled resource consumptionEPSS 1.1%CVE-2022-31801CRITICALInsufficient Verification of Data Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering toolEPSS 1.0%CVE-2021-34565CRITICALIn WirelessHART-Gateway versions 3.0.7 to 3.0.9 hard-coded credentials have been foundEPSS 1.0%CVE-2023-3569MEDIUMPHOENIX CONTACT: Denial-of-Service due to malicious XML files in TC ROUTER, TC CLOUD CLIENT and CLOUD CLIENTEPSS 1.0%CVE-2025-41703HIGHPhoenix Contact: UPS Shutdown via Unauthenticated Modbus CommandEPSS 1.0%CVE-2024-26004HIGHPHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer in CHARX SeriesEPSS 1.0%CVE-2026-22317HIGHCommand Injection Vulnerability in Root CA Certificate Transfer WorkflowEPSS 1.0%CVE-2021-34570HIGHPhoenix Contact: DoS for PLCnext Control devices in versions prior to 2021.0.5 LTSEPSS 1.0%CVE-2021-21002HIGHDenial of Service in Phoenix Contact FL COMSERVER UNI productsEPSS 1.0%CVE-2023-3573HIGHPHOENIX CONTACT: Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2021-21003MEDIUMDenial of Service Vulnerability in Phoenix Contact FL SWITCH SMCS series productsEPSS 0.9%CVE-2023-3570HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%