Vulnerabilidades em PHOENIX CONTACT

190 resultados
Análise Vexday

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2023-37861HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2023-0757CRITICALPhoenix Contact ProConOS prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2023-46141CRITICALPhoenix Contact: Automation Worx and classic line controllers prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2024-26001HIGHPHOENIX CONTACT: Out of bounds write only memory accessEPSS 0.9%CVE-2021-34561HIGHA vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through DNS rebindingEPSS 0.9%CVE-2023-37859HIGHPHOENIX CONTACT: Improper Privilege Management in WP 6xxx Web panelsEPSS 0.9%CVE-2026-27556HIGHLocal File Inclusion in /index.php/ajax/save_iodd_parametersEPSS 0.9%CVE-2020-12519HIGHPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use this vulnerability i.e. to open a reverse shell with root privileges.EPSS 0.9%CVE-2025-41699HIGHPhoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllersEPSS 0.8%CVE-2026-27555HIGHLocal File Inclusion in /index.php/ajax/get_iodd_port_infoEPSS 0.8%CVE-2024-26000MEDIUMPHOENIX CONTACT: Out of bounds read only memory accessEPSS 0.8%CVE-2023-37860HIGHPHOENIX CONTACT: Missing Authorization in WP 6xxx Web panelsEPSS 0.8%CVE-2021-34559MEDIUMA vulnerability in WirelessHART-Gateway <= 3.0.8 may allow remote attackers to rewrite links and URLs in cached pages to arbitrary stringsEPSS 0.8%CVE-2024-7699HIGHPhoenix Contact: OS command execution in MGUARD productsEPSS 0.8%CVE-2023-1109HIGHPHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web serviceEPSS 0.8%CVE-2024-28136HIGHPHOENIX CONTACT: command injection gains root privileges using the OCPP remote serviceEPSS 0.8%CVE-2020-12518MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.EPSS 0.7%CVE-2023-46142HIGHPHOENIX CONTACT: Insufficient Read and Write Protection to Logic and Runtime Data in PLCnext ControlEPSS 0.7%CVE-2024-43385HIGHPhoenix Contact: OS command execution through PROXY_HTTP_PORT in mGuard devicesEPSS 0.7%CVE-2024-43386HIGHPhoenix Contact: OS command execution through EMAIL_NOTIFICATION.TO in mGuard devices.EPSS 0.7%