Vulnerabilities > Phoenixcontact

DATE CVE VULNERABILITY TITLE RISK
2023-08-08 CVE-2023-3526 Cross-site Scripting vulnerability in Phoenixcontact products
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
network
low complexity
phoenixcontact CWE-79
critical
9.6
2023-08-08 CVE-2023-3569 XML Entity Expansion vulnerability in Phoenixcontact products
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.
network
low complexity
phoenixcontact CWE-776
4.9
2023-08-08 CVE-2023-3570 OS Command Injection vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device.
network
low complexity
phoenixcontact CWE-78
8.8
2023-08-08 CVE-2023-3571 OS Command Injection vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated to certificate operations to gain full access to the device.
network
low complexity
phoenixcontact CWE-78
8.8
2023-08-08 CVE-2023-3572 OS Command Injection vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.
network
low complexity
phoenixcontact CWE-78
critical
10.0
2023-08-08 CVE-2023-3573 OS Command Injection vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.
network
low complexity
phoenixcontact CWE-78
8.8
2023-06-13 CVE-2023-2673 Improper Validation of Specified Type of Input vulnerability in Phoenixcontact products
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
network
low complexity
phoenixcontact CWE-1287
5.3
2023-04-17 CVE-2023-1109 Unspecified vulnerability in Phoenixcontact products
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service.
network
low complexity
phoenixcontact
8.8
2022-11-15 CVE-2022-3461 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Phoenixcontact Automationworx Software Suite 1.89
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation.
local
low complexity
phoenixcontact CWE-119
7.8
2022-11-15 CVE-2022-3480 Allocation of Resources Without Limits or Throttling vulnerability in Phoenixcontact products
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s.
network
low complexity
phoenixcontact CWE-770
7.5