Vulnerabilidades en Phoenix Contact

190 resultados
Análisis Vexday

Com 74 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, os produtos Phoenix Contact apresentam taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata por parte de agentes maliciosos. No entanto, chama atenção o EPSS de 0,8113 associado à CVE-2014-9195, indicando alta probabilidade estatística de exploração e justificando priorização mesmo na ausência de registro formal no KEV. A falha mais recorrente é do tipo CWE-79 (Cross-Site Scripting), com 4 CVEs acompanhadas de prova de conceito pública, o que reduz a barreira técnica para tentativas de exploração. As 3 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo do portfólio, especialmente nos 2 registros de severidade crítica.

CVE-2023-37861HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2023-0757CRITICALPhoenix Contact ProConOS prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2023-46141CRITICALPhoenix Contact: Automation Worx and classic line controllers prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2024-26001HIGHPHOENIX CONTACT: Out of bounds write only memory accessEPSS 0.9%CVE-2021-34561HIGHA vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through DNS rebindingEPSS 0.9%CVE-2023-37859HIGHPHOENIX CONTACT: Improper Privilege Management in WP 6xxx Web panelsEPSS 0.9%CVE-2026-27556HIGHLocal File Inclusion in /index.php/ajax/save_iodd_parametersEPSS 0.9%CVE-2020-12519HIGHPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use this vulnerability i.e. to open a reverse shell with root privileges.EPSS 0.9%CVE-2025-41699HIGHPhoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllersEPSS 0.8%CVE-2026-27555HIGHLocal File Inclusion in /index.php/ajax/get_iodd_port_infoEPSS 0.8%CVE-2024-26000MEDIUMPHOENIX CONTACT: Out of bounds read only memory accessEPSS 0.8%CVE-2023-37860HIGHPHOENIX CONTACT: Missing Authorization in WP 6xxx Web panelsEPSS 0.8%CVE-2021-34559MEDIUMA vulnerability in WirelessHART-Gateway <= 3.0.8 may allow remote attackers to rewrite links and URLs in cached pages to arbitrary stringsEPSS 0.8%CVE-2024-7699HIGHPhoenix Contact: OS command execution in MGUARD productsEPSS 0.8%CVE-2023-1109HIGHPHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web serviceEPSS 0.8%CVE-2024-28136HIGHPHOENIX CONTACT: command injection gains root privileges using the OCPP remote serviceEPSS 0.8%CVE-2020-12518MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.EPSS 0.7%CVE-2023-46142HIGHPHOENIX CONTACT: Insufficient Read and Write Protection to Logic and Runtime Data in PLCnext ControlEPSS 0.7%CVE-2024-43385HIGHPhoenix Contact: OS command execution through PROXY_HTTP_PORT in mGuard devicesEPSS 0.7%CVE-2024-43386HIGHPhoenix Contact: OS command execution through EMAIL_NOTIFICATION.TO in mGuard devices.EPSS 0.7%