VYPR
Vendor

Phoenixcontact

Products
371
CVEs
174
Across products
680
Status
Private

Products

371
View all 371 products →

Recent CVEs

174
View all 174 CVEs →
  • CVE-2023-3572CriAug 8, 2023
    risk 0.65cvss 10.0epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.

  • CVE-2025-41769CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

  • CVE-2025-25270CriJul 8, 2025
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

  • CVE-2024-25995CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.

  • CVE-2023-46141CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

  • CVE-2023-0757CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.

  • CVE-2023-3935CriSep 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

  • CVE-2022-31801CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

  • CVE-2022-31800CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

  • CVE-2019-9201CriFeb 26, 2019
    risk 0.64cvss 9.8epss 0.03

    Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

  • CVE-2017-16743CriJan 12, 2018
    risk 0.64cvss 9.8epss 0.03

    An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service…

  • CVE-2017-5159CriFeb 13, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an mGuard device to Version 8.4.0 via the update-upload facility, the update will succeed, but it will reset the password of the admin user to its default value.

  • CVE-2023-3526CriAug 8, 2023
    risk 0.63cvss 9.6epss 0.02

    In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context…

  • CVE-2020-8768CriFeb 17, 2020
    risk 0.61cvss 9.4epss 0.02

    An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanism for read and write access to the configuration of the device. The mechanism can be discovered by examining a link on the website…

  • CVE-2018-10730CriMay 17, 2018
    risk 0.60cvss 9.1epss 0.05

    All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.

  • CVE-2022-29898CriMay 11, 2022
    risk 0.59cvss 9.1epss 0.01

    On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

  • CVE-2022-29897CriMay 11, 2022
    risk 0.59cvss 9.1epss 0.01

    On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.

  • CVE-2018-10731CriMay 17, 2018
    risk 0.59cvss 9.0epss 0.03

    All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728).

  • CVE-2017-10102CriAug 8, 2017
    risk 0.59cvss 9.0epss 0.03

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network…

  • CVE-2019-12869HigJun 24, 2019
    risk 0.58cvss 8.8epss 0.04

    An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-Of-Bounds Read, Information Disclosure, and remote code execution. The attacker needs to…