Vulnerabilidades em PHOENIX CONTACT

167 resultados
Análise Vexday

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2014-9195Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical FunctionEPSS 80.7%CVE-2020-12497HIGHPhoenix Contact Automation Worx <= 1.87: stack-based overflowEPSS 14.7%CVE-2016-8380The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.EPSS 11.2%CVE-2016-8371The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.EPSS 11.2%CVE-2025-41752HIGHReflected XSS vulnerability in pxc_portSfp.phpEPSS 9.8%CVE-2025-41747HIGHReflected XSS vulnerability in pxc_vlanIntfCfg.phpEPSS 9.8%CVE-2025-41750HIGHReflected XSS vulnerability in pxc_PortCfg.phpEPSS 9.8%CVE-2025-41746HIGHReflected XSS vulnerability in pxc_portSecCfg.phpEPSS 9.8%CVE-2025-41748HIGHReflected XSS vulnerability in pxc_Dot1xCfg.phpEPSS 9.8%CVE-2025-41751HIGHReflected XSS vulnerability in pxc_portCntr.phpEPSS 9.8%CVE-2016-8366Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pEPSS 5.8%CVE-2019-10953HIGHABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some conEPSS 3.4%CVE-2020-12498HIGHPhoenix Contact Automation Worx <= 1.87: out-of-bounds read remote code executionEPSS 2.1%CVE-2021-33542HIGHPhoenix Contact: Automation Worx Software Suite affected by Remote Code Execution (RCE) vulnerabilityEPSS 1.8%CVE-2025-41706MEDIUMPhoenix Contact: Webserver Denial of Service through Malformed Content-LengthEPSS 1.7%CVE-2023-3526CRITICALPHOENIX CONTACT: Cross-site Scripting vulnerability in TC ROUTER, TC CLOUD CLIENT and CLOUD CLIENT devicesEPSS 1.6%CVE-2025-41704MEDIUMPhoenix Contact: Unauthenticated Modbus Service DoS via Crafted Function CodeEPSS 1.5%CVE-2021-33541HIGHPhoenix Contact: ILC1x Industrial controllers affected by Denial-of-Service vulnerabilityEPSS 1.5%CVE-2025-41707MEDIUMPhoenix Contact: WebSocket Handler Denial of ServiceEPSS 1.5%CVE-2024-25998HIGHPHOENIX CONTACT: Command injection in the OCPP ServiceEPSS 1.5%