Phoenixcontact
phoenixcontact
156 CVEs • 680 products
Products (680)
Click to collapseToggle
Products (680)
Click to collapse
CVEs (156)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 May 14, 2024 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A low privileged remote attacker can use a command injection vulnerability in the API which performs
remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 May 14, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently l...Show more |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 May 14, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2
A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root
privileges.
|
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 8.7 HIGH· v3 N/A· v2 An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
|
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only. |
1Phoenixcontact 2Multiprog Proconos EclrJun 17, 2026 Dec 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity ch...Show more |
1Phoenixcontact 9Axc F 1152 Firmware Axc F 2152 FirmwareAxc F 3152 Firmware+6 moreJun 17, 2026 Dec 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices. |
1Phoenixcontact 18Automationworx Software Suite Axc 1050 FirmwareAxc 1050 Xc Firmware+15 moreJun 17, 2026 Dec 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. |
1Phoenixcontact 9Axc F 1152 Firmware Axc F 2152 FirmwareAxc F 3152 Firmware+6 moreJun 17, 2026 Dec 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices. |