Vulnerabilities > Phoenixcontact > Plcnext Engineer

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-46142 Incorrect Permission Assignment for Critical Resource vulnerability in Phoenixcontact products
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
network
low complexity
phoenixcontact CWE-732
8.8
2023-12-14 CVE-2023-46144 Download of Code Without Integrity Check vulnerability in Phoenixcontact products
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
network
low complexity
phoenixcontact CWE-494
6.5
2023-09-13 CVE-2023-3935 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
network
low complexity
wibu trumpf phoenixcontact CWE-787
critical
9.8
2020-07-21 CVE-2020-12499 Path Traversal vulnerability in Phoenixcontact Plcnext Engineer 202031
In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.
4.4