Vulnerabilidades en Phoenix Contact

190 resultados
Análisis Vexday

Com 74 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, os produtos Phoenix Contact apresentam taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata por parte de agentes maliciosos. No entanto, chama atenção o EPSS de 0,8113 associado à CVE-2014-9195, indicando alta probabilidade estatística de exploração e justificando priorização mesmo na ausência de registro formal no KEV. A falha mais recorrente é do tipo CWE-79 (Cross-Site Scripting), com 4 CVEs acompanhadas de prova de conceito pública, o que reduz a barreira técnica para tentativas de exploração. As 3 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo do portfólio, especialmente nos 2 registros de severidade crítica.

CVE-2026-41032HIGHPhoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllersEPSS 0.3%CVE-2024-26002HIGHPHOENIX CONTACT: File ownership manipulation in CHARX SeriesEPSS 0.3%CVE-2026-44094HIGHFallback to second RAUC slot with default credentialsEPSS 0.3%CVE-2025-25269HIGHLocal Privilege Escalation via Unauthenticated Command InjectionEPSS 0.3%CVE-2026-22322HIGHStored Cross‑Site Scripting in Link Aggregation Name HandlingEPSS 0.3%CVE-2024-28137HIGHPHOENIX CONTACT: privilege escalation due to a TOCTOU vulnerability in the CHARX Series EPSS 0.3%CVE-2026-44097MEDIUMFile Upload vulnerabilityEPSS 0.2%CVE-2021-34563LOWIn WirelessHART-Gateway versions 3.0.8 and 3.0.9 the HttpOnly flag is missing in a cookie which allows client-side javascript to modify itEPSS 0.2%CVE-2026-44103MEDIUMJupiCore does not perform validation of firmwareEPSS 0.2%CVE-2026-44095HIGHLocal Privilege Escalation via Network scriptsEPSS 0.2%CVE-2025-41697MEDIUMShell access to UART ConsoleEPSS 0.2%CVE-2026-44096HIGHudhcpc Privilege EscalationEPSS 0.2%CVE-2026-44093HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start scriptEPSS 0.2%CVE-2026-44099HIGHLocal Privilege Escalation via pppd password injectionEPSS 0.2%CVE-2026-44106HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website fileEPSS 0.2%CVE-2025-41669HIGHInsufficient Verification of Data AuthenticityEPSS 0.2%CVE-2022-3461HIGHBuffer Overflow in PHOENIX CONTACT Automationworx Software SuiteEPSS 0.2%CVE-2025-41696MEDIUMHardcoded User PasswordEPSS 0.2%CVE-2022-3737HIGHOut-of-bounds Read in PHOENIX CONTACT Automationworx Software SuiteEPSS 0.2%CVE-2026-44102MEDIUMOCPP Firmware download is not properly lockedEPSS 0.2%