Vulnerabilidades em PHOENIX CONTACT

190 resultados
Análise Vexday

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2026-41032HIGHPhoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllersEPSS 0.3%CVE-2024-26002HIGHPHOENIX CONTACT: File ownership manipulation in CHARX SeriesEPSS 0.3%CVE-2026-44094HIGHFallback to second RAUC slot with default credentialsEPSS 0.3%CVE-2025-25269HIGHLocal Privilege Escalation via Unauthenticated Command InjectionEPSS 0.3%CVE-2026-22322HIGHStored Cross‑Site Scripting in Link Aggregation Name HandlingEPSS 0.3%CVE-2024-28137HIGHPHOENIX CONTACT: privilege escalation due to a TOCTOU vulnerability in the CHARX Series EPSS 0.3%CVE-2026-44097MEDIUMFile Upload vulnerabilityEPSS 0.2%CVE-2021-34563LOWIn WirelessHART-Gateway versions 3.0.8 and 3.0.9 the HttpOnly flag is missing in a cookie which allows client-side javascript to modify itEPSS 0.2%CVE-2026-44103MEDIUMJupiCore does not perform validation of firmwareEPSS 0.2%CVE-2026-44095HIGHLocal Privilege Escalation via Network scriptsEPSS 0.2%CVE-2025-41697MEDIUMShell access to UART ConsoleEPSS 0.2%CVE-2026-44096HIGHudhcpc Privilege EscalationEPSS 0.2%CVE-2026-44093HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start scriptEPSS 0.2%CVE-2026-44099HIGHLocal Privilege Escalation via pppd password injectionEPSS 0.2%CVE-2026-44106HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website fileEPSS 0.2%CVE-2025-41669HIGHInsufficient Verification of Data AuthenticityEPSS 0.2%CVE-2022-3461HIGHBuffer Overflow in PHOENIX CONTACT Automationworx Software SuiteEPSS 0.2%CVE-2025-41696MEDIUMHardcoded User PasswordEPSS 0.2%CVE-2022-3737HIGHOut-of-bounds Read in PHOENIX CONTACT Automationworx Software SuiteEPSS 0.2%CVE-2026-44102MEDIUMOCPP Firmware download is not properly lockedEPSS 0.2%