Vulnerability index

Browse CVEs

135 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fl Nat Smn 8tx M Dmg Firmware HIGH 8.8
CVE-2019-9744

An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized…

Mitigation only
Fix from $1,950 2019-03-26
Ilc 131 Eth Firmware CRITICAL 9.8
CVE-2019-9201

Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as d…

No fix yet
Fix from $2,300 2019-02-26
Fl Switch 3005 Firmware CRITICAL 9.1
CVE-2018-10730

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.

Fix: after 1.33
Fix from $2,300 2018-05-17
Fl Switch 3005 Firmware CRITICAL 9.0
CVE-2018-10731

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very…

Fix: after 1.33
Fix from $2,300 2018-05-17
Fl Switch 3005 Firmware HIGH 8.1
CVE-2018-10728

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulne…

Fix: after 1.33
Fix from $1,950 2018-05-17
Fl Switch 3005 Firmware MEDIUM 5.3
CVE-2018-10729

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unaut…

Fix: after 1.33
Fix from $1,600 2018-05-17
Ilc Plcs Firmware HIGH 7.3
CVE-2016-8366EPSS 6%

Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by t…

No fix yet
Fix from $1,950 2018-04-05
Ilc Plcs Firmware HIGH 7.3
CVE-2016-8371EPSS 11%

The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

No fix yet
Fix from $1,950 2018-04-05
Ilc Plcs Firmware HIGH 7.3
CVE-2016-8380EPSS 11%

The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

No fix yet
Fix from $1,950 2018-04-05
Mguard Centerport Firmware HIGH 7.8
CVE-2018-5441

An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on…

Fix: after 8.6.0
Fix from $1,950 2018-01-30
Fl Switch 3005 Firmware CRITICAL 9.8
CVE-2017-16743

An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.3…

Fix: after 1.32
Fix from $2,300 2018-01-12
Fl Switch 3005 Firmware MEDIUM 5.3
CVE-2017-16741

An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32.…

Fix: after 1.32
Fix from $1,600 2018-01-12
Fl Comserver Basic 232 Firmware MEDIUM 6.1
CVE-2017-16723

A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422…

Mitigation only
Fix from $1,600 2017-12-11
Mguard Firmware CRITICAL 9.8
CVE-2017-5159

An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an mGuard device to Version 8.4.0 vi…

Mitigation only
Fix from $2,300 2017-02-13
Fl Il 24 Bk Pac MEDIUM 5.0
CVE-2008-7199

Phoenix Contact FL IL 24 BK-PAC allows remote attackers to cause a denial of service (hang) via (1) unspecified manipulations as demonstrated by a Ne…

Mitigation only
Fix from $1,600 2009-09-10