Vulnerabilities in PHOENIX CONTACT

167 results
Vexday analysis

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2025-41694MEDIUMAuthenticated Denial-of-Service via WebshellEPSS 0.4%CVE-2023-37856MEDIUMPHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsEPSS 0.4%CVE-2023-37855MEDIUMPHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsEPSS 0.4%CVE-2026-7849CRITICALCommand Injection in SCM (idledisconnect parameter)EPSS 0.4%CVE-2024-25999HIGHPHOENIX CONTACT: Privilege escalation in the OCPP agent serviceEPSS 0.4%CVE-2026-44090CRITICALMissing authentication for MQTT BrokerEPSS 0.4%CVE-2026-44101CRITICALOCPP reconfiguration vulnerabilityEPSS 0.4%CVE-2020-12499HIGHPHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier: Improper path sanitation vulnerability.EPSS 0.4%CVE-2018-25112HIGHPHOENIX CONTACT: ILC 1x1 ETH Denial of ServiceEPSS 0.4%CVE-2024-25996MEDIUMPHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX Series EPSS 0.4%CVE-2024-7698MEDIUMPhoenix Contact: Access to CSRF tokens of higher privileged users in MGUARD productsEPSS 0.4%CVE-2024-28133HIGHPHOENIX CONTACT: Privilege escalation in CHARX Series EPSS 0.4%CVE-2026-44092HIGHMissing input validation / stripping of CRLF characters in SystemConfigManagerEPSS 0.4%CVE-2026-22316MEDIUMBuffer Overflow using TFTP FilenameEPSS 0.4%CVE-2024-11497HIGHPhoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalationEPSS 0.4%CVE-2023-37862HIGHPHOENIX CONTACT: Missing Authorization in WP 6xxx Web panelsEPSS 0.4%CVE-2026-22321MEDIUMStack-Based Buffer Overflow in CLI Login Username Handling over CLIEPSS 0.4%CVE-2025-24002MEDIUMMQTT DoS Vulnerability in German EV Charging StationsEPSS 0.4%CVE-2025-24003HIGHMQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging StationsEPSS 0.3%CVE-2024-43384HIGHPhoenix Contact: Improper removal of sensitive information in MGUARD productsEPSS 0.3%