Vulnerabilities > Phoenixcontact

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-7699 OS Command Injection vulnerability in Phoenixcontact products
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
network
low complexity
phoenixcontact CWE-78
8.8
2024-09-10 CVE-2024-7734 Allocation of Resources Without Limits or Throttling vulnerability in Phoenixcontact products
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service.
network
low complexity
phoenixcontact CWE-770
5.3
2024-08-13 CVE-2024-3913 Files or Directories Accessible to External Parties vulnerability in Phoenixcontact products
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.
high complexity
phoenixcontact CWE-552
5.3
2023-08-09 CVE-2023-37856 Unspecified vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
network
low complexity
phoenixcontact
4.3
2023-08-09 CVE-2023-37857 Unspecified vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies.
network
low complexity
phoenixcontact
7.2
2023-08-09 CVE-2023-37858 Unspecified vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.
network
low complexity
phoenixcontact
4.9
2023-08-09 CVE-2023-37859 Unspecified vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.
network
low complexity
phoenixcontact
7.2
2022-11-09 CVE-2021-34579 Unspecified vulnerability in Phoenixcontact FL Mguard DM 1.12.0/1.13.0
In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read mGuard configuration profiles (“ATV profiles”).
network
low complexity
phoenixcontact
7.5
2022-02-02 CVE-2022-22509 Improper Privilege Management vulnerability in Phoenixcontact products
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
network
low complexity
phoenixcontact CWE-269
8.8
2021-11-10 CVE-2021-34582 Unspecified vulnerability in Phoenixcontact FL Mguard 1102 Firmware and FL Mguard 1105 Firmware
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.
network
low complexity
phoenixcontact
4.8