Vulnerabilidades en PHOENIX CONTACT

190 resultados
Análisis Vexday

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2023-37855MEDIUMPHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsEPSS 0.6%CVE-2023-37856MEDIUMPHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsEPSS 0.6%CVE-2024-43388HIGHPhoenix Contact: SNMP reconfiguration due to improper input validation in MGUARD devicesEPSS 0.6%CVE-2024-43387HIGHPhoenix Contact: Access files due to improper neutralization of special elements in MGUARD devicesEPSS 0.6%CVE-2025-41717HIGHConfig-Upload Code InjectionEPSS 0.6%CVE-2026-27552HIGHUnauthorized IODD File Upload due to Improper AuthorizationEPSS 0.6%CVE-2026-27553MEDIUMInformation Disclosure via Schema Path ManipulationEPSS 0.5%CVE-2024-43390HIGHPhoenix Contact: Firewall reconfiguration due to improper input validation in MGUARD devicesEPSS 0.5%CVE-2024-43391HIGHPhoenix Contact: Firewall reconfiguration through the FW_PORTFORWARDING.SRC_IP in MGUARD devicesEPSS 0.5%CVE-2024-43389HIGHPhoenix Contact: OSPF reconfiguration due to improper input validation in MGUARD devicesEPSS 0.5%CVE-2024-43393HIGHPhoenix Contact: Configuration changes of the firewall services can lead to DoS in MGUARD devicesEPSS 0.5%CVE-2024-43392HIGHPhoenix Contact: Firewall reconfiguration through the FW_environment variables in MGUARD devicesEPSS 0.5%CVE-2025-41667HIGHPhoenix Contact: File access due to the replacement of a critical file used by the arp-preinit scriptEPSS 0.5%CVE-2025-41693MEDIUMAuthenticated Denial-of-Service via SSHEPSS 0.5%CVE-2025-41668HIGHPhoenix Contact: File access due to the replacement of a critical file used by the service security-profileEPSS 0.5%CVE-2025-41666HIGHPhoenix Contact: File access due to the replacement of a critical file used by the watchdogEPSS 0.5%CVE-2026-44108CRITICALFirewall bypass during shutdownEPSS 0.5%CVE-2024-3913MEDIUMPhoenix Contact: Start sequence allows attack during the boot processEPSS 0.5%CVE-2024-6788HIGHPhoenix Contact: update feature from CHARX controller can be used to reset a low privilege user passwordEPSS 0.5%CVE-2023-37862HIGHPHOENIX CONTACT: Missing Authorization in WP 6xxx Web panelsEPSS 0.5%