Vulnerabilidades en Phoenix Contact

190 resultados
Análisis Vexday

Com 74 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, os produtos Phoenix Contact apresentam taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata por parte de agentes maliciosos. No entanto, chama atenção o EPSS de 0,8113 associado à CVE-2014-9195, indicando alta probabilidade estatística de exploração e justificando priorização mesmo na ausência de registro formal no KEV. A falha mais recorrente é do tipo CWE-79 (Cross-Site Scripting), com 4 CVEs acompanhadas de prova de conceito pública, o que reduz a barreira técnica para tentativas de exploração. As 3 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo do portfólio, especialmente nos 2 registros de severidade crítica.

CVE-2023-37855MEDIUMPHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsEPSS 0.6%CVE-2023-37856MEDIUMPHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsEPSS 0.6%CVE-2024-43388HIGHPhoenix Contact: SNMP reconfiguration due to improper input validation in MGUARD devicesEPSS 0.6%CVE-2024-43387HIGHPhoenix Contact: Access files due to improper neutralization of special elements in MGUARD devicesEPSS 0.6%CVE-2025-41717HIGHConfig-Upload Code InjectionEPSS 0.6%CVE-2026-27552HIGHUnauthorized IODD File Upload due to Improper AuthorizationEPSS 0.6%CVE-2026-27553MEDIUMInformation Disclosure via Schema Path ManipulationEPSS 0.5%CVE-2024-43390HIGHPhoenix Contact: Firewall reconfiguration due to improper input validation in MGUARD devicesEPSS 0.5%CVE-2024-43391HIGHPhoenix Contact: Firewall reconfiguration through the FW_PORTFORWARDING.SRC_IP in MGUARD devicesEPSS 0.5%CVE-2024-43389HIGHPhoenix Contact: OSPF reconfiguration due to improper input validation in MGUARD devicesEPSS 0.5%CVE-2024-43393HIGHPhoenix Contact: Configuration changes of the firewall services can lead to DoS in MGUARD devicesEPSS 0.5%CVE-2024-43392HIGHPhoenix Contact: Firewall reconfiguration through the FW_environment variables in MGUARD devicesEPSS 0.5%CVE-2025-41667HIGHPhoenix Contact: File access due to the replacement of a critical file used by the arp-preinit scriptEPSS 0.5%CVE-2025-41693MEDIUMAuthenticated Denial-of-Service via SSHEPSS 0.5%CVE-2025-41668HIGHPhoenix Contact: File access due to the replacement of a critical file used by the service security-profileEPSS 0.5%CVE-2025-41666HIGHPhoenix Contact: File access due to the replacement of a critical file used by the watchdogEPSS 0.5%CVE-2026-44108CRITICALFirewall bypass during shutdownEPSS 0.5%CVE-2024-3913MEDIUMPhoenix Contact: Start sequence allows attack during the boot processEPSS 0.5%CVE-2024-6788HIGHPhoenix Contact: update feature from CHARX controller can be used to reset a low privilege user passwordEPSS 0.5%CVE-2023-37862HIGHPHOENIX CONTACT: Missing Authorization in WP 6xxx Web panelsEPSS 0.5%