Vulnerabilities in PHOENIX CONTACT

167 results
Vexday analysis

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2023-37861HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2021-34598HIGHPhoenix Contact: FL MGUARD lack of memory release in remote logging functionalityEPSS 0.9%CVE-2020-12523MEDIUMPhoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled in the device configurationEPSS 0.9%CVE-2023-0757CRITICALPhoenix Contact ProConOS prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2023-46141CRITICALPhoenix Contact: Automation Worx and classic line controllers prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2024-26001HIGHPHOENIX CONTACT: Out of bounds write only memory accessEPSS 0.9%CVE-2025-41699HIGHPhoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllersEPSS 0.9%CVE-2021-34561HIGHA vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through DNS rebindingEPSS 0.9%CVE-2022-3480HIGHDenial-of-Service vulnerability in PHOENIX CONTACT mGuard product familyEPSS 0.9%CVE-2020-12519HIGHPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use this vulnerability i.e. to open a reverse shell with root privileges.EPSS 0.9%CVE-2024-26000MEDIUMPHOENIX CONTACT: Out of bounds read only memory accessEPSS 0.8%CVE-2023-3572CRITICALPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.8%CVE-2021-34559MEDIUMA vulnerability in WirelessHART-Gateway <= 3.0.8 may allow remote attackers to rewrite links and URLs in cached pages to arbitrary stringsEPSS 0.8%CVE-2024-7699HIGHPhoenix Contact: OS command execution in MGUARD productsEPSS 0.8%CVE-2023-1109HIGHPHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web serviceEPSS 0.8%CVE-2024-28136HIGHPHOENIX CONTACT: command injection gains root privileges using the OCPP remote serviceEPSS 0.8%CVE-2023-46142HIGHPHOENIX CONTACT: Insufficient Read and Write Protection to Logic and Runtime Data in PLCnext ControlEPSS 0.7%CVE-2024-43385HIGHPhoenix Contact: OS command execution through PROXY_HTTP_PORT in mGuard devicesEPSS 0.7%CVE-2024-43386HIGHPhoenix Contact: OS command execution through EMAIL_NOTIFICATION.TO in mGuard devices.EPSS 0.7%CVE-2020-12518MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.EPSS 0.7%