Phoenixcontact

Rfc 4072r

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 12.08.2026 08:06:48
  • Zuletzt bearbeitet 12.08.2026 13:17:18

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact...

  • EPSS 0.39%
  • Veröffentlicht 12.08.2026 08:06:26
  • Zuletzt bearbeitet 12.08.2026 17:17:23

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext serv...

  • EPSS 0.59%
  • Veröffentlicht 12.08.2026 08:05:54
  • Zuletzt bearbeitet 13.08.2026 16:17:50

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

  • EPSS 0.22%
  • Veröffentlicht 27.05.2026 07:18:28
  • Zuletzt bearbeitet 27.05.2026 14:53:22

The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to r...

  • EPSS 0.19%
  • Veröffentlicht 27.05.2026 07:17:43
  • Zuletzt bearbeitet 27.05.2026 14:53:22

A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data fro...