AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Phoenix Contact
PH
Platform

Phoenix Contact

PLCnext Technology, AXC F PLCs, FL SWITCH Ethernet, and comprehensive ICS cybersecurity portfolio.

https://www.phoenixcontact.com →
85
Total CVEs
0
Resources
12
CRIT
54
HIGH
18
MED
1
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
12 / 85
CVE-2023-3572CRITICAL

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.

Aug 8, 2023
10.0
CVE-2023-46141CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

Dec 14, 2023
9.8
CVE-2023-0757CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.

Dec 14, 2023
9.8
CVE-2019-9201CRITICAL

Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

Feb 26, 2019
9.8
CVE-2017-16743CRITICAL

An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.

Jan 12, 2018
9.8
CVE-2017-5159CRITICAL

An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an mGuard device to Version 8.4.0 via the update-upload facility, the update will succeed, but it will reset the password of the admin user to its default value.

Feb 13, 2017
9.8
CVE-2023-3526CRITICAL

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.

Aug 8, 2023
9.6
CVE-2020-8768CRITICAL

An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanism for read and write access to the configuration of the device. The mechanism can be discovered by examining a link on the website of the device.

Feb 17, 2020
9.4
CVE-2022-29898CRITICAL

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

May 11, 2022
9.1
CVE-2022-29897CRITICAL

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.

May 11, 2022
9.1
CVE-2018-10730CRITICAL

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.

May 17, 2018
9.1
CVE-2018-10731CRITICAL

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728).

May 17, 2018
9.0
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2023-3572CRITICAL
10.0
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated …Aug 8, 2023›
CVE-2023-46141CRITICAL
9.8
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOE…Dec 14, 2023›
CVE-2023-0757CRITICAL
9.8
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PH…Dec 14, 2023›
CVE-2019-9201CRITICAL
9.8
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and o…Feb 26, 2019›
CVE-2017-16743CRITICAL
9.8
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Se…Jan 12, 2018›
CVE-2017-5159CRITICAL
9.8
An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. W…Feb 13, 2017›
CVE-2023-3526CRITICAL
9.6
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIEN…Aug 8, 2023›
CVE-2020-8768CRITICAL
9.4
An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L be…Feb 17, 2020›
CVE-2022-29898CRITICAL
9.1
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration fil…May 11, 2022›
CVE-2022-29897CRITICAL
9.1
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utilit…May 11, 2022›
CVE-2018-10730CRITICAL
9.1
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33…May 17, 2018›
CVE-2018-10731CRITICAL
9.0
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33…May 17, 2018›