VYPR

Vendor CVEs

Phoenixcontact

All CVEs

174 total · sorted by risk
  • CVE-2024-43393HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP…

  • CVE-2024-43392HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable…

  • CVE-2024-43391HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.

  • CVE-2024-43390HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.

  • CVE-2024-43389HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.

  • CVE-2023-37862HigAug 9, 2023
    risk 0.53cvss 8.2epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.

  • CVE-2020-12499HigJul 21, 2020
    risk 0.53cvss 8.2epss 0.00

    In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.

  • CVE-2019-18352HigFeb 18, 2020
    risk 0.53cvss 8.2epss 0.00

    Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2GC-2SFP devices before V2.90 when using MAC-based port security.

  • CVE-2018-13992HigMay 7, 2019
    risk 0.53cvss 8.2epss 0.01

    The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.

  • CVE-2018-10728HigMay 17, 2018
    risk 0.53cvss 8.1epss 0.02

    All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731).

  • CVE-2017-10078HigAug 8, 2017
    risk 0.53cvss 8.1epss 0.02

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting). The supported version that is affected is Java SE: 8u131. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE.…

  • CVE-2024-43384HigMay 7, 2026
    risk 0.52cvss 8.0epss 0.00

    A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.

  • CVE-2020-12497HigJul 1, 2020
    risk 0.52cvss 7.8epss 0.15

    PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

  • CVE-2025-24006HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

  • CVE-2025-24005HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

  • CVE-2024-28137HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.

  • CVE-2024-28136HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.01

    A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.

  • CVE-2024-28133HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. 

  • CVE-2024-26002HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.

  • CVE-2022-3737HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks…

  • CVE-2022-3461HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised…

  • CVE-2021-34597HigNov 4, 2021
    risk 0.51cvss 7.8epss 0.01

    Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.

  • CVE-2021-33542HigJun 25, 2021
    risk 0.51cvss 7.8epss 0.02

    Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely…

  • CVE-2020-12498HigJul 1, 2020
    risk 0.51cvss 7.8epss 0.02

    mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

  • CVE-2020-10940HigMar 27, 2020
    risk 0.51cvss 7.8epss 0.00

    Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.

  • CVE-2020-10939HigMar 27, 2020
    risk 0.51cvss 7.8epss 0.00

    Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.

  • CVE-2019-16675HigOct 31, 2019
    risk 0.51cvss 7.8epss 0.03

    An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original…

  • CVE-2016-8380HigApr 5, 2018
    risk 0.51cvss 7.3epss 0.11

    The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

  • CVE-2016-8371HigApr 5, 2018
    risk 0.51cvss 7.3epss 0.11

    The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

  • CVE-2016-8366HigApr 5, 2018
    risk 0.51cvss 7.3epss 0.06

    Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.

  • CVE-2018-5441HigJan 30, 2018
    risk 0.51cvss 7.8epss 0.00

    An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed…

  • CVE-2025-41770HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

  • CVE-2026-41032HigJun 3, 2026
    risk 0.49cvss 7.5epss 0.00

    It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

  • CVE-2024-26004HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.

  • CVE-2024-26003HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality. 

  • CVE-2023-5592HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.00

    Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of…

  • CVE-2023-46143HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.00

    Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.

  • CVE-2023-37860HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.

  • CVE-2022-3480HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for…

  • CVE-2021-34579HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.01

    In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web…

  • CVE-2021-34598HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.01

    In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active

  • CVE-2021-34570HigSep 27, 2021
    risk 0.49cvss 7.5epss 0.01

    Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.

  • CVE-2021-33541HigJun 25, 2021
    risk 0.49cvss 7.5epss 0.01

    Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to…

  • CVE-2021-21005HigJun 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.

  • CVE-2021-21002HigJun 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.

  • CVE-2020-12524HigDec 2, 2020
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).

  • CVE-2020-9435HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.01

    PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded…

  • CVE-2018-16994HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 devices and Bosch Rexroth S20-ETH-BK and Rexroth S20-PN-BK+ (the S20-PN-BK+/S20-ETH-BK fieldbus couplers sold by Bosch Rexroth contain technology from Phoenix…

  • CVE-2018-13994HigMay 7, 2019
    risk 0.49cvss 7.5epss 0.02

    The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections.

  • CVE-2019-10953HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.03

    ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.