Plcnext Engineer
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3935 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2023 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | ||
| CVE-2023-46142 | Hig | 0.57 | 8.8 | 0.01 | Dec 14, 2023 | A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices. | ||
| CVE-2020-12499 | Hig | 0.53 | 8.2 | 0.00 | Jul 21, 2020 | In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files. | ||
| CVE-2025-41770 | Hig | 0.49 | 7.5 | 0.00 | Aug 12, 2026 | An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted. | ||
| CVE-2023-46144 | Med | 0.42 | 6.5 | 0.00 | Dec 14, 2023 | A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices. |
- risk 0.64cvss 9.8epss 0.01
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
- risk 0.57cvss 8.8epss 0.01
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
- risk 0.53cvss 8.2epss 0.00
In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.
- risk 0.49cvss 7.5epss 0.00
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.
- risk 0.42cvss 6.5epss 0.00
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.