Show filters
158 Total Results
Displaying 131-140 of 158
Sort by:
Attacker Value
Unknown
CVE-2018-10728
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731).
0
Attacker Value
Unknown
CVE-2016-8371
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.
0
Attacker Value
Unknown
CVE-2016-8366
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.
0
Attacker Value
Unknown
CVE-2016-8380
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
0
Attacker Value
Unknown
CVE-2018-5441
Disclosure Date: January 30, 2018 (last updated November 26, 2024)
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages.
0
Attacker Value
Unknown
CVE-2018-5697
Disclosure Date: January 14, 2018 (last updated November 26, 2024)
Icy Phoenix 2.2.0.105 allows SQL injection via an unapprove request to admin_kb_art.php or the order parameter to admin_jr_admin.php, related to functions_kb.php.
0
Attacker Value
Unknown
CVE-2017-16741
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on the device to read diagnostic information.
0
Attacker Value
Unknown
CVE-2017-16743
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.
0
Attacker Value
Unknown
CVE-2017-16723
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The cross-site scripting vulnerability has been identified, which may allow remote code execution.
0
Attacker Value
Unknown
CVE-2017-1000163
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.
0