← Back

Phoenixcontact

phoenixcontact

156 CVEs • 680 products

Products (680)

Click to collapse
Toggle

CVEs (156)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phoenixcontact
1Automationworx Software Suite
Jun 17, 2026
Jun 24, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to a Use-After-Free and remote code execut...Show more
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to a Use-After-Free and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.Show less
1Phoenixcontact
2Axc F 2152 Firmware
Axc F 2152 Starterkit Firmware
Jun 17, 2026
Jun 18, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD...Show more
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD card manipulation may lead to an authentication bypass opportunity.Show less
1Phoenixcontact
2Axc F 2152 Firmware
Axc F 2152 Starterkit Firmware
Jun 17, 2026
Jun 17, 2019
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker...Show more
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually via a Linux shell.Show less
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections.
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 7, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 7, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images.
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 6, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.
5Abb
PhoenixcontactSchneider Electric+2 more
106ed1052 1cc01 0ba8 Firmware
6es7211 1ae40 0xb0 Firmware6es7314 6eh04 0ab0 Firmware+7 more
Jun 17, 2026
Apr 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network...Show more
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.Show less
1Phoenixcontact
4Fl Nat Smcs 8tx Firmware
Fl Nat Smn 8tx M Dmg FirmwareFl Nat Smn 8tx M Firmware+1 more
Jun 17, 2026
Mar 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP add...Show more
An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP address as an authenticated user, because this IP address is used as a session identifier.Show less
1Phoenixcontact
2Rad 80211 Xd/hp Bus Firmware
Rad 80211 Xd Firmware
Jun 17, 2026
Mar 26, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component.
1Phoenixcontact
8Axc 1050 Firmware
Ilc 131 Eth/xc FirmwareIlc 131 Eth Firmware+5 more
Jun 17, 2026
Feb 26, 2019
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all director...Show more
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.Show less
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 17, 2018
N/A· v4
9.0 CRITICAL· v3
9.3 HIGH· v2
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728).
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 17, 2018
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 17, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user.
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 17, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731).
1Phoenixcontact
1Ilc Plcs Firmware
Nov 21, 2024
Apr 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
1Phoenixcontact
1Ilc Plcs Firmware
Nov 21, 2024
Apr 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.
1Phoenixcontact
1Ilc Plcs Firmware
Nov 21, 2024
Apr 5, 2018
N/A· v4
7.3 HIGH· v3
5.0 MEDIUM· v2
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the passwor...Show more
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.Show less
1Phoenixcontact
23Mguard Centerport Firmware
Mguard Core Tx Vpn FirmwareMguard Delta Tx/tx Firmware+20 more
Jun 17, 2026
Jan 30, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the u...Show more
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages.Show less