Vulnerabilities > Phoenixcontact

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-0757 Incorrect Permission Assignment for Critical Resource vulnerability in Phoenixcontact Multiprog and Proconos Eclr
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.
network
low complexity
phoenixcontact CWE-732
critical
9.8
2023-12-14 CVE-2023-46141 Incorrect Permission Assignment for Critical Resource vulnerability in Phoenixcontact products
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
network
low complexity
phoenixcontact CWE-732
critical
9.8
2023-12-14 CVE-2023-46142 Incorrect Permission Assignment for Critical Resource vulnerability in Phoenixcontact products
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
network
low complexity
phoenixcontact CWE-732
8.8
2023-12-14 CVE-2023-46143 Download of Code Without Integrity Check vulnerability in Phoenixcontact products
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
network
low complexity
phoenixcontact CWE-494
7.5
2023-12-14 CVE-2023-46144 Download of Code Without Integrity Check vulnerability in Phoenixcontact products
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
network
low complexity
phoenixcontact CWE-494
6.5
2023-12-14 CVE-2023-5592 Download of Code Without Integrity Check vulnerability in Phoenixcontact Multiprog and Proconos Eclr
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.
network
low complexity
phoenixcontact CWE-494
7.5
2023-09-13 CVE-2023-3935 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
network
low complexity
wibu trumpf phoenixcontact CWE-787
critical
9.8
2023-08-09 CVE-2023-37855 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.
network
low complexity
phoenixcontact CWE-610
4.3
2023-08-09 CVE-2023-37856 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
network
low complexity
phoenixcontact CWE-610
4.3
2023-08-09 CVE-2023-37857 Use of Hard-coded Credentials vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies.
network
low complexity
phoenixcontact CWE-798
7.2