Show filters
133 Total Results
Displaying 51-60 of 133
Sort by:
Attacker Value
Unknown

CVE-2023-3573

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.
Attacker Value
Unknown

CVE-2023-3572

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.
Attacker Value
Unknown

CVE-2023-3571

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated to certificate operations to gain full access to the device.
Attacker Value
Unknown

CVE-2023-3570

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device.
Attacker Value
Unknown

CVE-2023-3569

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.
Attacker Value
Unknown

CVE-2023-3526

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
Attacker Value
Unknown

CVE-2023-2673

Disclosure Date: June 13, 2023 (last updated October 08, 2023)
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
Attacker Value
Unknown

CVE-2023-1109

Disclosure Date: April 17, 2023 (last updated October 08, 2023)
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
Attacker Value
Unknown

CVE-2022-3461

Disclosure Date: November 15, 2022 (last updated December 22, 2024)
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
Attacker Value
Unknown

CVE-2022-3737

Disclosure Date: November 15, 2022 (last updated December 22, 2024)
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.