Vulnerability index

Browse CVEs

135 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fl Switch Smcs 16tx Firmware MEDIUM 6.1
CVE-2021-21004

In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based manag…

Fix: after 4.70
Fix from $1,600 2021-06-25
Fl Switch Smcs 16tx Firmware MEDIUM 5.3
CVE-2021-21003

In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-E…

Fix: after 4.70
Fix from $1,600 2021-06-25
Plcnext Firmware CRITICAL 9.8
CVE-2020-12519

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root p…

Fix: 2021.0+
Fix from $2,300 2020-12-17
Tc Mguard Rs4000 4g Vzw Vpn Firmware CRITICAL 9.1
CVE-2020-12523

On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. …

Fix: 8.8.3+
Fix from $2,300 2020-12-17
Plcnext Firmware MEDIUM 6.5
CVE-2020-12521

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET …

Fix: 2021.0+
Fix from $1,600 2020-12-17
Plcnext Firmware CRITICAL 9.0
CVE-2020-12517

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to g…

Fix: 2021.0+
Fix from $2,300 2020-12-17
Plcnext Firmware MEDIUM 5.5
CVE-2020-12518

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protecte…

Fix: 2021.0+
Fix from $1,600 2020-12-17
Btp 2043w Firmware HIGH 7.5
CVE-2020-12524

Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unr…

Mitigation only
Fix from $1,950 2020-12-02
Plcnext Engineer HIGH 7.3
CVE-2020-12499

In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.

Fix: after 2020-3-1
Fix from $1,950 2020-07-21
Pc Worx HIGH 7.8
CVE-2020-12497EPSS 15%

PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC W…

Fix: 1.87+
Fix from $1,950 2020-07-01
Pc Worx HIGH 7.8
CVE-2020-12498

mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. M…

Fix: 1.87+
Fix from $1,950 2020-07-01
Portico Server 1 Client HIGH 7.8
CVE-2020-10940

Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.

Fix: after 3.0.7
Fix from $1,950 2020-03-27
Pc Worx Srt HIGH 7.8
CVE-2020-10939

Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.

Fix: after 1.14
Fix from $1,950 2020-03-27
Tc Router 3002t 4g Firmware HIGH 8.8
CVE-2020-9436

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT t…

Fix: after 2.05.3
Fix from $1,950 2020-03-12
Tc Router 3002t 4g Firmware HIGH 7.5
CVE-2020-9435

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT t…

Fix: after 2.05.3
Fix from $1,950 2020-03-12
Axl F Bk Pn Firmware HIGH 7.5
CVE-2018-16994

An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 devices and Bosch Rexroth S20-ETH-B…

Fix: after 1.12
Fix from $1,950 2020-02-18
Fl Nat 2208 Firmware HIGH 8.2
CVE-2019-18352

Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2GC-2SFP devices before V2.90 when using MAC-based…

Fix: 2.90+
Fix from $1,950 2020-02-18
Ilc 2050 Bi Firmware CRITICAL 9.4
CVE-2020-8768

An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanis…

Fix: 1.2.3+
Fix from $2,300 2020-02-17
Config\+ HIGH 7.8
CVE-2019-16675

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Con…

Fix: after 1.86
Fix from $1,950 2019-10-31
Automationworx Software Suite HIGH 8.8
CVE-2019-12869

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Con…

Fix: after 1.86
Fix from $1,950 2019-06-24
Automationworx Software Suite HIGH 8.8
CVE-2019-12870

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Con…

Fix: after 1.86
Fix from $1,950 2019-06-24
Automationworx Software Suite HIGH 8.8
CVE-2019-12871

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Con…

Fix: after 1.86
Fix from $1,950 2019-06-24
Axc F 2152 Firmware MEDIUM 6.8
CVE-2019-10998

An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices…

Fix: 2019.0_lts+
Fix from $1,600 2019-06-18
Axc F 2152 Firmware MEDIUM 5.9
CVE-2019-10997

An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices…

Fix: 2019.0_lts+
Fix from $1,600 2019-06-17
Fl Switch 3005 Firmware CRITICAL 9.8
CVE-2018-13992

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.

Fix: after 1.34
Fix from $2,300 2019-05-07
Fl Switch 3005 Firmware HIGH 8.8
CVE-2018-13993

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.

Fix: after 1.34
Fix from $1,950 2019-05-07
Fl Switch 3005 Firmware HIGH 7.5
CVE-2018-13994

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 conn…

Fix: after 1.34
Fix from $1,950 2019-05-07
Fl Switch 3005 Firmware MEDIUM 5.3
CVE-2018-13991

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images.

Fix: after 1.34
Fix from $1,600 2019-05-07
Fl Switch 3005 Firmware CRITICAL 9.8
CVE-2018-13990

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction …

Fix: 1.35+
Fix from $2,300 2019-05-06
Rad 80211 Xd\/hp Bus Firmware HIGH 8.8
CVE-2019-9743

An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component.

No fix yet
Fix from $1,950 2019-03-26