Vulnerabilities
Vulnerable Software
Phoenixcontact:  Security Vulnerabilities
An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-03-12
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-12-14
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-12-14
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
CVSS Score
6.5
EPSS Score
0.0
Published
2023-12-14
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-12-14
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-12-14
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
CVSS Score
8.8
EPSS Score
0.003
Published
2023-12-14
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
CVSS Score
9.8
EPSS Score
0.002
Published
2023-09-13
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.
CVSS Score
8.8
EPSS Score
0.011
Published
2023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
CVSS Score
8.2
EPSS Score
0.003
Published
2023-08-09


Contact Us

Shodan ® - All rights reserved