Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phoenixcontact pc worx vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2019-16675
An issue exists in PHOENIX CONTACT PC Worx up to and including 1.86, PC Worx Express up to and including 1.86, and Config+ up to and including 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to ...
Phoenixcontact Pc Worx Express
Phoenixcontact Config\\+
Phoenixcontact Pc Worx
5.1
CVSSv2
CVE-2021-33542
Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialize...
Phoenixcontact Config\\+
Phoenixcontact Pc Worx
Phoenixcontact Pc Worx Express
6.8
CVSSv2
CVE-2020-12497
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and previous versions can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.
Phoenixcontact Pc Worx
Phoenixcontact Pc Worx Express
6.8
CVSSv2
CVE-2020-12498
mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and previous versions is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.
Phoenixcontact Pc Worx
Phoenixcontact Pc Worx Express
6.8
CVSSv2
CVE-2021-34597
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.
Phoenixcontact Pc Worx
Phoenixcontact Pc Worx Express
NA
CVE-2023-46141
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated malicious user to gain full access of the affected device.
Phoenixcontact Automationworx Software Suite
Phoenixcontact Axc 1050 Firmware
Phoenixcontact Axc 1050 Xc Firmware
Phoenixcontact Axc 3050 Firmware
Phoenixcontact Config\\+
Phoenixcontact Fc 350 Pci Eth Firmware
Phoenixcontact Ilc1x0 Firmware
Phoenixcontact Ilc1x1 Firmware
Phoenixcontact Ilc 3xx Firmware
Phoenixcontact Pc Worx
Phoenixcontact Pc Worx Express
Phoenixcontact Pc Worx Rt Basic Firmware
Phoenixcontact Pc Worx Srt
Phoenixcontact Rfc 430 Eth-ib Firmware
Phoenixcontact Rfc 450 Eth-ib Firmware
Phoenixcontact Rfc 460r Pn 3tx Firmware
Phoenixcontact Rfc 470s Pn 3tx Firmware
Phoenixcontact Rfc 480s Pn 4tx Firmware
NA
CVE-2023-46143
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote malicious user to modify some or all applications on a PLC.
Phoenixcontact Automationworx Software Suite
Phoenixcontact Axc 1050 Firmware
Phoenixcontact Axc 1050 Xc Firmware
Phoenixcontact Axc 3050 Firmware
Phoenixcontact Config\\+
Phoenixcontact Fc 350 Pci Eth Firmware
Phoenixcontact Ilc1x0 Firmware
Phoenixcontact Ilc1x1 Firmware
Phoenixcontact Ilc 3xx Firmware
Phoenixcontact Pc Worx
Phoenixcontact Pc Worx Express
Phoenixcontact Pc Worx Rt Basic Firmware
Phoenixcontact Pc Worx Srt
Phoenixcontact Rfc 430 Eth-ib Firmware
Phoenixcontact Rfc 450 Eth-ib Firmware
Phoenixcontact Rfc 460r Pn 3tx Firmware
Phoenixcontact Rfc 470s Pn 3tx Firmware
Phoenixcontact Rfc 480s Pn 4tx Firmware
4.6
CVSSv2
CVE-2020-10939
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT up to and including 1.14 allow for local privilege escalation.
Phoenixcontact Pc Worx Srt
7.1
CVSSv2
CVE-2019-10997
An issue exists on Phoenix Contact AXC F 2152 (No.2404267) prior to 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) prior to 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC s...
Phoenixcontact Axc F 2152 Firmware
Phoenixcontact Axc F 2152 Starterkit Firmware
6.8
CVSSv2
CVE-2019-12870
An issue exists in PHOENIX CONTACT PC Worx up to and including 1.86, PC Worx Express up to and including 1.86, and Config+ up to and including 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized Pointer and remote code execution. The attacker needs ...
Phoenixcontact Automationworx Software Suite
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »