Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
229 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Phoenixcontact AXL F BK PN FirmwarePhoenixcontact AXL F BK ETH FirmwarePhoenixcontact AXL F BK ETH XC Firmware | 18/2/2020 | 17/6/2026 | An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 devices and Bosch Rexroth S20-ETH-BK and Rexroth S20-PN-BK+ (the S20-PN-BK+/S20-ETH-BK fieldbus couplers sold by Bosch Rexroth contain technology from Phoenix Contact). Incorrect handling of a request with… | |
| Modificada | Alta (8.2) | 0.44% | — | Phoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp Firmware | 18/2/2020 | 17/6/2026 | Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2GC-2SFP devices before V2.90 when using MAC-based port security. | |
| Modificada | Crítica (9.4) | 1.8% | — | Phoenixcontact ILC 2050 BI FirmwarePhoenixcontact ILC 2050 Bi-l Firmware | 17/2/2020 | 17/6/2026 | An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanism for read and write access to the configuration of the device. The mechanism can be discovered by examining a link on the website of the device. | |
| Modificada | Alta (8.8) | 1.3% | — | Phoenix Securecore Technology | 13/11/2019 | 17/6/2026 | In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges. Adverse impacts are limited to the Windows environment and there is no known direct impact to the UEFI firmware. This was fixed in late June 2019. | |
| Modificada | Alta (7.8) | 3.3% | — | Phoenixcontact Config+Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 31/10/2019 | 17/6/2026 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to… | |
| Modificada | Alta (8.8) | 3.7% | — | Phoenixcontact Automationworx Software Suite | 24/6/2019 | 17/6/2026 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized Pointer and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be… | |
| Modificada | Alta (8.8) | 3.8% | — | Phoenixcontact Automationworx Software Suite | 24/6/2019 | 17/6/2026 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-Of-Bounds Read, Information Disclosure, and remote code execution. The attacker needs to get access to an original PC Worx or… | |
| Modificada | Alta (8.8) | 3.7% | — | Phoenixcontact Automationworx Software Suite | 24/6/2019 | 17/6/2026 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to a Use-After-Free and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to… | |
| Modificada | Media (6.8) | 0.40% | — | Phoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 2152 Starterkit Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD card manipulation may lead to an authentication bypass opportunity. | |
| Modificada | Media (5.9) | 1.0% | — | Phoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 2152 Starterkit Firmware | 17/6/2019 | 17/6/2026 | An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually… | |
| Modificada | Alta (7.5) | 2.2% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections. | |
| Modificada | Alta (8.8) | 0.86% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default. | |
| Modificada | Media (5.3) | 1.6% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images. | |
| Modificada | Crítica (9.8) | 2.3% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 6/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts. | |
| Modificada | Alta (7.5) | 3.4% | — | ABB Pm554-tp-eth FirmwarePhoenixcontact ILC 151 ETH FirmwareSchneider-electric Modicon M221 FirmwareSiemens 6es7211-1ae40-0xb0 Firmware+6 | 17/4/2019 | 17/6/2026 | ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets. | |
| Modificada | Alta (8.8) | 1.6% | — | Phoenixcontact FL NAT SMN 8tx-m-dmg FirmwarePhoenixcontact FL NAT SMN 8tx-m FirmwarePhoenixcontact FL NAT SMN 8TX FirmwarePhoenixcontact FL NAT Smcs 8TX Firmware | 26/3/2019 | 17/6/2026 | An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP address as an authenticated user, because this IP address is used as a session identifier. | |
| Modificada | Alta (8.8) | 3.5% | — | Phoenixcontact Rad-80211-xd/hp-bus FirmwarePhoenixcontact Rad-80211-xd Firmware | 26/3/2019 | 17/6/2026 | An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component. | |
| Modificada | Crítica (9.8) | 3.1% | — | Phoenixcontact ILC 131 ETH FirmwarePhoenixcontact ILC 131 Eth/xc FirmwarePhoenixcontact ILC 151 ETH FirmwarePhoenixcontact ILC 151 Eth/xc Firmware+4 | 26/2/2019 | 17/6/2026 | Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories. | |
| Modificada | Crítica (9) | 2.7% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728). | |
| Modificada | Crítica (9.1) | 4.5% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection. | |
| Modificada | Media (5.3) | 1.9% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user. | |
| Modificada | Alta (8.1) | 2.2% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731). | |
| Modificada | Alta (7.3) | 11% | 💥 Exploit | Phoenixcontact ILC Plcs Firmware | 5/4/2018 | 17/6/2026 | The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication. | |
| Modificada | Alta (7.3) | 11% | 💥 Exploit | Phoenixcontact ILC Plcs Firmware | 5/4/2018 | 17/6/2026 | The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled. |