Vulnerabilidades en Phoenix Contact

190 resultados
Análisis Vexday

Com 74 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, os produtos Phoenix Contact apresentam taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata por parte de agentes maliciosos. No entanto, chama atenção o EPSS de 0,8113 associado à CVE-2014-9195, indicando alta probabilidade estatística de exploração e justificando priorização mesmo na ausência de registro formal no KEV. A falha mais recorrente é do tipo CWE-79 (Cross-Site Scripting), com 4 CVEs acompanhadas de prova de conceito pública, o que reduz a barreira técnica para tentativas de exploração. As 3 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo do portfólio, especialmente nos 2 registros de severidade crítica.

CVE-2024-28134HIGHPHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX Series EPSS 0.5%CVE-2025-41694MEDIUMAuthenticated Denial-of-Service via WebshellEPSS 0.5%CVE-2024-7734MEDIUMPhoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.EPSS 0.5%CVE-2026-7849CRITICALCommand Injection in SCM (idledisconnect parameter)EPSS 0.5%CVE-2025-41705MEDIUMPhoenix Contact: WebSocket Message Interception Leaks Webfrontend CredentialsEPSS 0.5%CVE-2018-25112HIGHPHOENIX CONTACT: ILC 1x1 ETH Denial of ServiceEPSS 0.5%CVE-2020-12521MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.EPSS 0.5%CVE-2023-37858MEDIUMPHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsEPSS 0.5%CVE-2026-44101CRITICALOCPP reconfiguration vulnerabilityEPSS 0.4%CVE-2026-44090CRITICALMissing authentication for MQTT BrokerEPSS 0.4%CVE-2023-37864HIGHPHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity checkEPSS 0.4%CVE-2026-44092HIGHMissing input validation / stripping of CRLF characters in SystemConfigManagerEPSS 0.4%CVE-2025-41770HIGHUnauthenticated Denial of ServiceEPSS 0.4%CVE-2024-25999HIGHPHOENIX CONTACT: Privilege escalation in the OCPP agent serviceEPSS 0.4%CVE-2024-7698MEDIUMPhoenix Contact: Access to CSRF tokens of higher privileged users in MGUARD productsEPSS 0.4%CVE-2020-12499HIGHPHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier: Improper path sanitation vulnerability.EPSS 0.4%CVE-2024-25996MEDIUMPHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX Series EPSS 0.4%CVE-2024-11497HIGHPhoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalationEPSS 0.4%CVE-2024-28133HIGHPHOENIX CONTACT: Privilege escalation in CHARX Series EPSS 0.4%CVE-2026-22316MEDIUMBuffer Overflow using TFTP FilenameEPSS 0.4%