Vulnerabilidades en Phoenix Contact

190 resultados
Análisis Vexday

Com 74 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, os produtos Phoenix Contact apresentam taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata por parte de agentes maliciosos. No entanto, chama atenção o EPSS de 0,8113 associado à CVE-2014-9195, indicando alta probabilidade estatística de exploração e justificando priorização mesmo na ausência de registro formal no KEV. A falha mais recorrente é do tipo CWE-79 (Cross-Site Scripting), com 4 CVEs acompanhadas de prova de conceito pública, o que reduz a barreira técnica para tentativas de exploração. As 3 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo do portfólio, especialmente nos 2 registros de severidade crítica.

CVE-2026-22321MEDIUMStack-Based Buffer Overflow in CLI Login Username Handling over CLIEPSS 0.4%CVE-2025-24002MEDIUMMQTT DoS Vulnerability in German EV Charging StationsEPSS 0.4%CVE-2026-44091HIGHCreation of a new configuration by posting a malicious ID to MQTTEPSS 0.4%CVE-2025-24003HIGHMQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging StationsEPSS 0.3%CVE-2024-43384HIGHPhoenix Contact: Improper removal of sensitive information in MGUARD productsEPSS 0.3%CVE-2026-22318MEDIUMStack-Based Buffer Overflow in File Transfer Parameter HandlingEPSS 0.3%CVE-2026-22319MEDIUMStack-Based Buffer Overflow in File Install Parameter HandlingEPSS 0.3%CVE-2023-46143HIGHPhoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLCEPSS 0.3%CVE-2023-5592HIGHPhoenix Contact: ProConOs prone to Download of Code Without Integrity CheckEPSS 0.3%CVE-2026-22320MEDIUMStack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLIEPSS 0.3%CVE-2023-46144MEDIUMPHOENIX CONTACT: PLCnext Control prone to download of code without integrity checkEPSS 0.3%CVE-2024-26288HIGHPHOENIX CONTACT: Lack of SSL support in CHARX SeriesEPSS 0.3%CVE-2026-44107HIGHExposed Reboot via ModbusEPSS 0.3%CVE-2025-41665MEDIUMPhoenix Contact: DoS of the PLC due to incorrect default permissions possibleEPSS 0.3%CVE-2026-44100HIGHJupiCore charging point reconfiguration without authEPSS 0.3%CVE-2025-25268HIGHUnauthenticated Configuration Access via Exposed API EndpointEPSS 0.3%CVE-2025-41692MEDIUMWeak/Predictable root PasswordEPSS 0.3%CVE-2021-34582MEDIUMPhoenix Contact: FL MGUARD XSS through web-based management and REST APIEPSS 0.3%CVE-2025-25271HIGHOCPP Backend Configuration via Insecure DefaultsEPSS 0.3%CVE-2026-44104CRITICALControllerAgent does not perform validation of firmwareEPSS 0.3%