Výsledky hledání

výrobce: Phoenix Contact× v celém archivu zrušit filtry

27 karet z 29 položek CZ · EN/orig

2

[Control Systems] Phoenix Contact security advisory (AV26-927)

Serial number: AV26-927Date: September 16, 2026 As of September 16, 2026, Phoenix Contact is affected by vulnerabilities in the following products: ICE2-8IOL-G65L-V1D Prior to 1.7.4 ICE2-8IOL-K45P-RJ45 Prior to 1.7.4 ICE2-8IOL-K45S-RJ45 Prior to 1.7.4 ICE2-8IOL1-G65L-V1D Prior to 1.7.4 ICE3-8IOL-G65L-V1D Prior to 1.7.4 ICE3-8IOL-G65L-V1D-Y Prior to 1.7.4 ICE3-8IOL-K45P-RJ45 Prior to 1.7.4 ICE3-8IOL-K45S-RJ45 Prior to 1.7.4 ICE3-8IOL1-G65L-V1D Prior to 1.7.4 IOL MA8 EIP DI8 Prior to 1.7.4 IOL…

Phoenix Contact Pepperl+Fuchs Carlo Gavazzi Automation CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] Phoenix Contact security advisory (AV26-927)

Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices

[VDE-2026-027] The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.

Phoenix Contact DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices

2

[Control Systems] Phoenix Contact security advisory (AV26-811)

Serial number: AV26-811Date: August 12, 2026 As of August 12, 2026, Phoenix Contact is affected by vulnerabilities in the following products: AXC F 1152 Prior to 2026.0.3 AXC F 1252 Prior to 2026.0.3 AXC F 2000 EA Prior to 2026.0.3 AXC F 2152 Prior to 2026.0.3 AXC F 3152 Prior to 2026.0.3 BPC 9102S Prior to 2026.0.3 BPC 9202S Prior to 2026.0.3 Catan C1 Prior to 2026.0.3 EPC 1502 Prior to 2026.0.3 EPC 1522 Prior to 2026.0.3 RFC 4072R Prior to 2026.0.3 RFC 4072S Prior to 2026.0.3 VL3 UPC 2440…

Phoenix Contact výroba a průmysl energetika vodárenství CA

· Cyber Centre Kanada · [Control Systems] Phoenix Contact security advisory (AV26-811)

Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

[vde-2025-056] This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.

EPSS 0.01 CVE-2025-41769 CVE-2025-41770 CVE-2025-41771 Phoenix Contact DE

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

21

Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

[VDE-2026-008] Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.

Phoenix Contact energetika doprava DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

ZDI-26-502: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44106.

EPSS 0.00 CVSS 7.8 CVE-2026-44106 Phoenix Contact výroba a průmysl US

· Zero Day Initiative · ZDI-26-502: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability

ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerability

This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-44108.

EPSS 0.01 CVSS 6.4 CVE-2026-44108 Phoenix Contact US

· Zero Day Initiative · ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerability

ZDI-26-504: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-7849.

EPSS 0.00 CVSS 7.5 CVE-2026-7849 Phoenix Contact US

· Zero Day Initiative · ZDI-26-504: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability

ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability

This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44092.

EPSS 0.00 CVSS 5.0 CVE-2026-44092 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability

ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-44105.

EPSS 0.00 CVSS 5.3 CVE-2026-44105 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability

ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44096.

EPSS 0.00 CVSS 7.8 CVE-2026-44096 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability

SPOJENO PŘES CVE ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44095.

EPSS 0.00 CVSS 7.8 CVE-2026-44095 Phoenix Contact US

· Zero Day Initiative · ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability

ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability

This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44101.

EPSS 0.00 CVSS 5.0 CVE-2026-44101 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability

ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to bypass firmware validation on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44104.

EPSS 0.00 CVSS 7.5 CVE-2026-44104 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability

ZDI-26-511: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44093.

EPSS 0.00 CVSS 7.8 CVE-2026-44093 Phoenix Contact US

· Zero Day Initiative · ZDI-26-511: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability

ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability

This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44107.

EPSS 0.00 CVSS 6.5 CVE-2026-44107 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability

ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability

This vulnerability allows network-adjacent attackers to upload arbitrary files on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-44097.

EPSS 0.00 CVSS 2.4 CVE-2026-44097 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability

ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerability

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44094.

EPSS 0.00 CVSS 7.5 CVE-2026-44094 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerability

ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability

This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.2. The following CVEs are assigned: CVE-2026-44100.

EPSS 0.00 CVSS 4.2 CVE-2026-44100 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability

ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability

This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44090.

EPSS 0.00 CVSS 6.5 CVE-2026-44090 Phoenix Contact výroba a průmysl energetika US

· Zero Day Initiative · ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability

ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098.

EPSS 0.01 CVSS 6.8 CVE-2026-44098 Phoenix Contact energetika US

· Zero Day Initiative · ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability

ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to access internal resources on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2026-44091.

EPSS 0.00 CVSS 6.3 CVE-2026-44091 Phoenix Contact US

· Zero Day Initiative · ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability

ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44099.

EPSS 0.00 CVSS 7.5 CVE-2026-44099 Phoenix Contact výroba a průmysl US

· Zero Day Initiative · ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability

ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44103.

EPSS 0.00 CVSS 7.5 CVE-2026-44103 Phoenix Contact US

· Zero Day Initiative · ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability

SPOJENO PŘES CVE ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.

EPSS 0.00 CVSS 6.5 CVE-2026-41032 Phoenix Contact US DE

tg: zranitelnost tp: průmyslové systémy

· Zero Day Initiative · ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability · CERT@VDE · Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers

1

Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files

[VDE-2026-050] This advisory addresses security issues in PLCnext firmware versions prior to 2026.0.3 that are related to APP handling and the processing of configuration files. The identified vulnerabilities affect APP installation authenticity as well as the handling of configuration data in writable directories. Successful exploitation may allow authenticated attackers with different privilege levels to compromise integrity, availability, and system security of affected PLCnext Control. Both…

EPSS 0.00 CVE-2025-41669 CVE-2025-41670 Phoenix Contact DE

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files

1

Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL

[VDE-2026-023] Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.

EPSS 0.48 CVE-2025-15467 CVE-2025-69419 Phoenix Contact OpenSSL DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL