VYPR
Vendor

Phoenix

Products
10
CVEs
12
Across products
13
Status
Private

Products

10

Recent CVEs

12
  • CVE-2019-18279HigNov 13, 2019
    risk 0.57cvss 8.8epss 0.01

    In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges. Adverse impacts are limited to the Windows environment and there is no known direct impact to the UEFI firmware. This was fixed…

  • CVE-2023-31100HigNov 15, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: * from 4.3.0.0 before 4.3.0.203 * from 4.3.1.0 before 4.3.1.163 * from 4.4.0.0 before…

  • CVE-2023-35841HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.

  • CVE-2023-5058HigDec 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution.

  • CVE-2024-1598HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.00

    Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for Intel Gemini Lake.This issue affects: SecureCore™ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.

  • CVE-2024-0762HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects: Phoenix SecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCore™ for Intel Coffee Lake: from 4.1.0.1…

  • CVE-2020-12048HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.00

    Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management…

  • CVE-2025-40727MedJun 16, 2025
    risk 0.33cvss epss 0.01

    A Reflected Cross Site Scripting (XSS) vulnerability was found in '/search' in Phoenix Site CMS from Phoenix, which allows remote attackers to execute arbitrary code via 's' GET parameter.

  • CVE-2024-12533LowMay 13, 2025
    risk 0.21cvss 3.3epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore Technology 4 allows Input Data Manipulation.This issue affects SecureCore Technology 4: from 4.0.1.0 before 4.0.1.1018, from 4.1.0.1 before 4.1.0.573, from 4.2.0.1 before 4.2.0.338, from…

  • CVE-2024-29980LowJan 14, 2025
    risk 0.15cvss 2.3epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Manipulation.This…

  • CVE-2024-29979LowJan 14, 2025
    risk 0.15cvss 2.3epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Manipulation.This…

  • CVE-2010-5223Sep 6, 2012
    risk 0.00cvss epss 0.00

    Multiple untrusted search path vulnerabilities in Phoenix Project Manager 2.1.0.8 allow local users to gain privileges via a Trojan horse (1) wbtrv32.dll or (2) w3btrv7.dll file in the current working directory, as demonstrated by a directory that contains a .ppx file. NOTE:…