← Back

Phoenixcontact

phoenixcontact

156 CVEs • 680 products

Products (680)

Click to collapse
Toggle

CVEs (156)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phoenixcontact
4Energy Axc Pu
Infobox FirmwareSmartrtu Axc Ig Firmware+1 more
Jun 17, 2026
Apr 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and downl...Show more
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.Show less
1Phoenixcontact
1Automationworx Software Suite
Jun 17, 2026
Nov 15, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application...Show more
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.Show less
1Phoenixcontact
31Fl Mguard Centerport Firmware
Fl Mguard Centerport Vpn 1000 FirmwareFl Mguard Core Tx Firmware+28 more
Jun 17, 2026
Nov 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from d...Show more
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue. Show less
1Phoenixcontact
1Automationworx Software Suite
Jun 17, 2026
Nov 15, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an...Show more
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.Show less
1Phoenixcontact
1Fl Mguard Dm
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during ins...Show more
In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read mGuard configuration profiles (“ATV profiles”). Such configuration profiles may contain sensitive information, e.g. private keys associated with IPsec VPN connections.Show less
2Phoenixcontact
Phoenixcontact Software
3Multiprog
ProconosProconos Eclr
Jun 17, 2026
Jun 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
1Phoenixcontact
17Axc 1050 Firmware
Axc 1050 Xc FirmwareAxc 3050 Firmware+14 more
Jun 17, 2026
Jun 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
1Phoenixcontact
3Rad Ism 900 En Bd Bus Firmware
Rad Ism 900 En Bd/b FirmwareRad Ism 900 En Bd Firmware
Jun 17, 2026
May 11, 2022
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an int...Show more
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.Show less
1Phoenixcontact
3Rad Ism 900 En Bd Bus Firmware
Rad Ism 900 En Bd/b FirmwareRad Ism 900 En Bd Firmware
Jun 17, 2026
May 11, 2022
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation i...Show more
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.Show less
1Phoenixcontact
65Fl Switch 2005 Firmware
Fl Switch 2008 FirmwareFl Switch 2008f Firmware+62 more
Jun 17, 2026
Feb 2, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
1Phoenixcontact
2Fl Mguard 1102 Firmware
Fl Mguard 1105 Firmware
Jun 17, 2026
Nov 10, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active
1Phoenixcontact
2Fl Mguard 1102 Firmware
Fl Mguard 1105 Firmware
Jun 17, 2026
Nov 10, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.
1Phoenixcontact
2Pc Worx
Pc Worx Express
Jun 17, 2026
Nov 4, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project...Show more
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.Show less
1Phoenixcontact
6Axc F 1152 Firmware
Axc F 2152 FirmwareAxc F 2152 Starterkit Firmware+3 more
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.
1Phoenixcontact
3Config+
Pc WorxPc Worx Express
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.0 HIGH· v3
5.1 MEDIUM· v2
Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when un...Show more
Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities. Automated systems in operation which were programmed with one of the above-mentioned products are not affected.Show less
1Phoenixcontact
2Ilc1x0 Firmware
Ilc1x1 Firmware
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures....Show more
Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to cause a denial of service on the PLC's network communication module. A successful attack stops all network communication. To restore the network connectivity the device needs to be restarted. The automation task is not affected.Show less
1Phoenixcontact
18Axl F Bk Eip Ef Firmware
Axl F Bk Eip FirmwareAxl F Bk Eth Firmware+15 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.
1Phoenixcontact
15Fl Nat Smn 8tx M Firmware
Fl Nat Smn 8tx FirmwareFl Switch Smcs 14tx/2fx Sm Firmware+12 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device nee...Show more
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.Show less
1Phoenixcontact
15Fl Nat Smn 8tx M Firmware
Fl Nat Smn 8tx FirmwareFl Switch Smcs 14tx/2fx Sm Firmware+12 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.
1Phoenixcontact
15Fl Nat Smn 8tx M Firmware
Fl Nat Smn 8tx FirmwareFl Switch Smcs 14tx/2fx Sm Firmware+12 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected...Show more
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.Show less