Vulnerabilidades em Phoenix Contact

167 resultados
Análise Vexday

Com 74 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, os produtos Phoenix Contact apresentam taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata por parte de agentes maliciosos. No entanto, chama atenção o EPSS de 0,8113 associado à CVE-2014-9195, indicando alta probabilidade estatística de exploração e justificando priorização mesmo na ausência de registro formal no KEV. A falha mais recorrente é do tipo CWE-79 (Cross-Site Scripting), com 4 CVEs acompanhadas de prova de conceito pública, o que reduz a barreira técnica para tentativas de exploração. As 3 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo do portfólio, especialmente nos 2 registros de severidade crítica.

CVE-2022-31800CRITICALInsufficient Verification of Data Vulnerability in PHOENIX CONTACT classic line industrial controllersEPSS 1.5%CVE-2024-25995CRITICALPHOENIX CONTACT: Remote code execution in CHARX SeriesEPSS 1.4%CVE-2026-44098HIGHOS Command Injection in OCPP Agent via charge_box_idEPSS 1.4%CVE-2022-29897CRITICALRemote Code Execution in all versions of various RAD-ISM-900-EN-* devices by PHOENIX CONTACTEPSS 1.3%CVE-2024-28135MEDIUMPHOENIX CONTACT: command injection vulnerability in the API of the CHARX SeriesEPSS 1.3%CVE-2021-33555HIGHA vulnerability may allow remote attackers to read arbitrary files on the server of the WirelessHART-GatewayEPSS 1.2%CVE-2024-26003HIGHPHOENIX CONTACT: DoS of the control agent in CHARX SeriesEPSS 1.2%CVE-2020-12517HIGHPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).EPSS 1.1%CVE-2020-12524HIGHPhoenix Contact BTP Touch Panels uncontrolled resource consumptionEPSS 1.1%CVE-2022-31801CRITICALInsufficient Verification of Data Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering toolEPSS 1.0%CVE-2021-34565CRITICALIn WirelessHART-Gateway versions 3.0.7 to 3.0.9 hard-coded credentials have been foundEPSS 1.0%CVE-2023-3569MEDIUMPHOENIX CONTACT: Denial-of-Service due to malicious XML files in TC ROUTER, TC CLOUD CLIENT and CLOUD CLIENTEPSS 1.0%CVE-2025-41703HIGHPhoenix Contact: UPS Shutdown via Unauthenticated Modbus CommandEPSS 1.0%CVE-2024-26004HIGHPHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer in CHARX SeriesEPSS 1.0%CVE-2026-22317HIGHCommand Injection Vulnerability in Root CA Certificate Transfer WorkflowEPSS 1.0%CVE-2021-34570HIGHPhoenix Contact: DoS for PLCnext Control devices in versions prior to 2021.0.5 LTSEPSS 1.0%CVE-2021-21002HIGHDenial of Service in Phoenix Contact FL COMSERVER UNI productsEPSS 1.0%CVE-2023-3573HIGHPHOENIX CONTACT: Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2021-21003MEDIUMDenial of Service Vulnerability in Phoenix Contact FL SWITCH SMCS series productsEPSS 0.9%CVE-2023-3570HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%