Vulnerabilities > Phoenixcontact > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-0757 Incorrect Permission Assignment for Critical Resource vulnerability in Phoenixcontact Multiprog and Proconos Eclr
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.
network
low complexity
phoenixcontact CWE-732
critical
9.8
2023-12-14 CVE-2023-46141 Incorrect Permission Assignment for Critical Resource vulnerability in Phoenixcontact products
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
network
low complexity
phoenixcontact CWE-732
critical
9.8
2023-09-13 CVE-2023-3935 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
network
low complexity
wibu trumpf phoenixcontact CWE-787
critical
9.8
2023-08-08 CVE-2023-3526 Cross-site Scripting vulnerability in Phoenixcontact products
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
network
low complexity
phoenixcontact CWE-79
critical
9.6
2023-08-08 CVE-2023-3572 OS Command Injection vulnerability in Phoenixcontact products
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.
network
low complexity
phoenixcontact CWE-78
critical
10.0
2022-06-21 CVE-2022-31800 Insufficient Verification of Data Authenticity vulnerability in Phoenixcontact products
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
network
low complexity
phoenixcontact CWE-345
critical
10.0
2022-06-21 CVE-2022-31801 Insufficient Verification of Data Authenticity vulnerability in multiple products
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
network
low complexity
phoenixcontact phoenixcontact-software CWE-345
critical
10.0
2022-05-11 CVE-2022-29897 Improper Input Validation vulnerability in Phoenixcontact products
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.
network
low complexity
phoenixcontact CWE-20
critical
9.0
2022-05-11 CVE-2022-29898 Improper Validation of Integrity Check Value vulnerability in Phoenixcontact products
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.
network
low complexity
phoenixcontact CWE-354
critical
9.0
2022-02-02 CVE-2022-22509 Improper Privilege Management vulnerability in Phoenixcontact products
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
network
low complexity
phoenixcontact CWE-269
critical
9.0