Vulnerabilidades em PHOENIX CONTACT

190 resultados
Análise Vexday

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2014-9195Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical FunctionEPSS 80.7%CVE-2020-12497HIGHPhoenix Contact Automation Worx <= 1.87: stack-based overflowEPSS 14.7%CVE-2016-8380The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.EPSS 10.9%CVE-2016-8371The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.EPSS 10.9%CVE-2025-41747HIGHReflected XSS vulnerability in pxc_vlanIntfCfg.phpEPSS 9.8%CVE-2025-41748HIGHReflected XSS vulnerability in pxc_Dot1xCfg.phpEPSS 9.8%CVE-2025-41746HIGHReflected XSS vulnerability in pxc_portSecCfg.phpEPSS 9.8%CVE-2025-41752HIGHReflected XSS vulnerability in pxc_portSfp.phpEPSS 9.8%CVE-2025-41750HIGHReflected XSS vulnerability in pxc_PortCfg.phpEPSS 9.8%CVE-2025-41751HIGHReflected XSS vulnerability in pxc_portCntr.phpEPSS 9.8%CVE-2016-8366Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pEPSS 5.7%CVE-2019-10953HIGHABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some conEPSS 3.4%CVE-2026-27562HIGHCommand Injection via PUT in /api/iodd/configEPSS 2.2%CVE-2026-27560HIGHCommand Injection via DELETE in /api/status/dataEPSS 2.2%CVE-2026-27561HIGHCommand Injection via GET in /api/iodd/configEPSS 2.2%CVE-2026-27554HIGHCommand Injection in /index.php/ajax/save_iodd_parametersEPSS 2.1%CVE-2026-27550HIGHCommand Injection in Field_Shadow_Password ClassEPSS 2.1%CVE-2026-27551HIGHCommand Injection in /index.php/ajax/parameterManageEPSS 2.1%CVE-2026-27549HIGHCommand Injection in /index.php/attached_devices_tab/do_uploadEPSS 2.1%CVE-2026-27558HIGHCommand Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_filesEPSS 2.1%