Výsledky hledání

výrobce: Phoenix Contact sektor: energetika v celém archivu

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.

zrušit filtry CZ · EN/orig

12 karet z 12 položek

1

[Control Systems] Phoenix Contact security advisory (AV26-811)

Serial number: AV26-811Date: August 12, 2026 As of August 12, 2026, Phoenix Contact is affected by vulnerabilities in the following products: AXC F 1152 Prior to 2026.0.3 AXC F 1252 Prior to 2026.0.3 AXC F 2000 EA Prior to 2026.0.3 AXC F 2152 Prior to 2026.0.3 AXC F 3152 Prior to 2026.0.3 BPC 9102S Prior to 2026.0.3 BPC 9202S Prior to 2026.0.3 Catan C1 Prior to 2026.0.3 EPC 1502 Prior to 2026.0.3 EPC 1522 Prior to 2026.0.3 RFC 4072R Prior to 2026.0.3 RFC 4072S Prior to 2026.0.3 VL3 UPC 2440…

Phoenix Contact výroba a průmysl energetika vodárenství CA

Cyber Centre Kanada ·

11

ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability

This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44092.

EPSS 0.00 CVSS 5.0 CVE-2026-44092 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-44105.

EPSS 0.00 CVSS 5.3 CVE-2026-44105 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44096.

EPSS 0.00 CVSS 7.8 CVE-2026-44096 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability

This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44101.

EPSS 0.00 CVSS 5.0 CVE-2026-44101 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to bypass firmware validation on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44104.

EPSS 0.00 CVSS 7.5 CVE-2026-44104 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability

This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44107.

EPSS 0.00 CVSS 6.5 CVE-2026-44107 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability

This vulnerability allows network-adjacent attackers to upload arbitrary files on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-44097.

EPSS 0.00 CVSS 2.4 CVE-2026-44097 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerability

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44094.

EPSS 0.00 CVSS 7.5 CVE-2026-44094 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability

This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.2. The following CVEs are assigned: CVE-2026-44100.

EPSS 0.00 CVSS 4.2 CVE-2026-44100 Phoenix Contact energetika US

Zero Day Initiative ·

ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability

This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44090.

EPSS 0.00 CVSS 6.5 CVE-2026-44090 Phoenix Contact výroba a průmysl energetika US

Zero Day Initiative ·

ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098.

EPSS 0.01 CVSS 6.8 CVE-2026-44098 Phoenix Contact energetika US

Zero Day Initiative ·