Vulnerabilities in PHOENIX CONTACT

167 results
Vexday analysis

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2026-22318MEDIUMStack-Based Buffer Overflow in File Transfer Parameter HandlingEPSS 0.3%CVE-2023-37858MEDIUMPHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsEPSS 0.3%CVE-2026-22319MEDIUMStack-Based Buffer Overflow in File Install Parameter HandlingEPSS 0.3%CVE-2023-46143HIGHPhoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLCEPSS 0.3%CVE-2023-5592HIGHPhoenix Contact: ProConOs prone to Download of Code Without Integrity CheckEPSS 0.3%CVE-2026-44091HIGHCreation of a new configuration by posting a malicious ID to MQTTEPSS 0.3%CVE-2023-37864HIGHPHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity checkEPSS 0.3%CVE-2026-22320MEDIUMStack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLIEPSS 0.3%CVE-2026-44107HIGHExposed Reboot via ModbusEPSS 0.3%CVE-2023-46144MEDIUMPHOENIX CONTACT: PLCnext Control prone to download of code without integrity checkEPSS 0.3%CVE-2024-26288HIGHPHOENIX CONTACT: Lack of SSL support in CHARX SeriesEPSS 0.3%CVE-2025-41665MEDIUMPhoenix Contact: DoS of the PLC due to incorrect default permissions possibleEPSS 0.3%CVE-2025-25268HIGHUnauthenticated Configuration Access via Exposed API EndpointEPSS 0.3%CVE-2025-25271HIGHOCPP Backend Configuration via Insecure DefaultsEPSS 0.3%CVE-2021-34582MEDIUMPhoenix Contact: FL MGUARD XSS through web-based management and REST APIEPSS 0.3%CVE-2026-44100HIGHJupiCore charging point reconfiguration without authEPSS 0.3%CVE-2025-41692MEDIUMWeak/Predictable root PasswordEPSS 0.3%CVE-2026-41032HIGHPhoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllersEPSS 0.3%CVE-2024-26002HIGHPHOENIX CONTACT: File ownership manipulation in CHARX SeriesEPSS 0.3%CVE-2026-44094HIGHFallback to second RAUC slot with default credentialsEPSS 0.3%