Show filters
158 Total Results
Displaying 41-50 of 158
Sort by:
Attacker Value
Unknown

CVE-2024-25995

Disclosure Date: March 12, 2024 (last updated January 30, 2025)
An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.
0
Attacker Value
Unknown

CVE-2024-25994

Disclosure Date: March 12, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
0
Attacker Value
Unknown

CVE-2024-25415

Disclosure Date: February 16, 2024 (last updated January 14, 2025)
A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.
Attacker Value
Unknown

CVE-2023-5592

Disclosure Date: December 14, 2023 (last updated December 22, 2023)
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.
Attacker Value
Unknown

CVE-2023-46144

Disclosure Date: December 14, 2023 (last updated October 01, 2024)
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
Attacker Value
Unknown

CVE-2023-46143

Disclosure Date: December 14, 2023 (last updated December 22, 2023)
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
Attacker Value
Unknown

CVE-2023-46142

Disclosure Date: December 14, 2023 (last updated December 22, 2023)
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
Attacker Value
Unknown

CVE-2023-46141

Disclosure Date: December 14, 2023 (last updated December 22, 2023)
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
Attacker Value
Unknown

CVE-2023-0757

Disclosure Date: December 14, 2023 (last updated December 22, 2023)
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.
Attacker Value
Unknown

CVE-2023-5058

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution.