Vulnerabilities in PHOENIX CONTACT

167 results
Vexday analysis

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2026-22322HIGHStored Cross‑Site Scripting in Link Aggregation Name HandlingEPSS 0.3%CVE-2024-28137HIGHPHOENIX CONTACT: privilege escalation due to a TOCTOU vulnerability in the CHARX Series EPSS 0.3%CVE-2026-44097MEDIUMFile Upload vulnerabilityEPSS 0.2%CVE-2026-44104CRITICALControllerAgent does not perform validation of firmwareEPSS 0.2%CVE-2025-25269HIGHLocal Privilege Escalation via Unauthenticated Command InjectionEPSS 0.2%CVE-2021-34563LOWIn WirelessHART-Gateway versions 3.0.8 and 3.0.9 the HttpOnly flag is missing in a cookie which allows client-side javascript to modify itEPSS 0.2%CVE-2026-44103MEDIUMJupiCore does not perform validation of firmwareEPSS 0.2%CVE-2026-44099HIGHLocal Privilege Escalation via pppd password injectionEPSS 0.2%CVE-2026-44096HIGHudhcpc Privilege EscalationEPSS 0.2%CVE-2026-44106HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website fileEPSS 0.2%CVE-2026-44095HIGHLocal Privilege Escalation via Network scriptsEPSS 0.2%CVE-2026-44093HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start scriptEPSS 0.2%CVE-2025-41669HIGHInsufficient Verification of Data AuthenticityEPSS 0.2%CVE-2025-41697MEDIUMShell access to UART ConsoleEPSS 0.2%CVE-2026-44102MEDIUMOCPP Firmware download is not properly lockedEPSS 0.2%CVE-2021-34560MEDIUMA vulnerability in WirelessHART-Gateway <= 3.0.9 could lead to information exposure of sensitive informationEPSS 0.2%CVE-2022-3461HIGHBuffer Overflow in PHOENIX CONTACT Automationworx Software SuiteEPSS 0.2%CVE-2022-3737HIGHOut-of-bounds Read in PHOENIX CONTACT Automationworx Software SuiteEPSS 0.2%CVE-2025-41670HIGHUntrusted Search PathEPSS 0.2%CVE-2025-41696MEDIUMHardcoded User PasswordEPSS 0.2%