Vulnerabilities > Phoenixcontact > Multiprog

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-0757 Incorrect Permission Assignment for Critical Resource vulnerability in Phoenixcontact Multiprog and Proconos Eclr
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.
network
low complexity
phoenixcontact CWE-732
critical
9.8
2023-12-14 CVE-2023-5592 Download of Code Without Integrity Check vulnerability in Phoenixcontact Multiprog and Proconos Eclr
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.
network
low complexity
phoenixcontact CWE-494
7.5
2022-06-21 CVE-2022-31801 Insufficient Verification of Data Authenticity vulnerability in multiple products
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
network
low complexity
phoenixcontact phoenixcontact-software CWE-345
critical
10.0