Show filters
133 Total Results
Displaying 111-120 of 133
Sort by:
Attacker Value
Unknown
CVE-2018-10729
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user.
0
Attacker Value
Unknown
CVE-2018-10730
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.
0
Attacker Value
Unknown
CVE-2018-10728
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731).
0
Attacker Value
Unknown
CVE-2016-8371
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.
0
Attacker Value
Unknown
CVE-2016-8366
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.
0
Attacker Value
Unknown
CVE-2016-8380
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
0
Attacker Value
Unknown
CVE-2018-5441
Disclosure Date: January 30, 2018 (last updated November 26, 2024)
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages.
0
Attacker Value
Unknown
CVE-2017-16741
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on the device to read diagnostic information.
0
Attacker Value
Unknown
CVE-2017-16743
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.
0
Attacker Value
Unknown
CVE-2017-16723
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The cross-site scripting vulnerability has been identified, which may allow remote code execution.
0