VendorsPHOENIX CONTACTaxc_f_2152all versions
Vulnerabilities

PHOENIX CONTACT AXC F 2152

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-12519
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
Published 2020-12-17 · Modified
10.0EPSS 0.009
CVE-2020-12517
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).
Published 2020-12-17 · Modified
9.0EPSS 0.011
CVE-2023-46142
PHOENIX CONTACT: Insufficient Read and Write Protection to Logic and Runtime Data in PLCnext Control
Published 2023-12-14 · Modified
8.8EPSS 0.007
CVE-2021-34570
Phoenix Contact: DoS for PLCnext Control devices in versions prior to 2021.0.5 LTS
Published 2021-09-27 · Modified
7.8EPSS 0.010
CVE-2019-10997
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually via a Linux shell.
Published 2019-06-17 · Modified
7.1EPSS 0.010
CVE-2019-10998
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD card manipulation may lead to an authentication bypass opportunity.
Published 2019-06-18 · Modified
6.8EPSS 0.004
CVE-2020-12521
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.
Published 2020-12-17 · Modified
6.5EPSS 0.005
CVE-2023-46144
PHOENIX CONTACT: PLCnext Control prone to download of code without integrity check
Published 2023-12-14 · Modified
6.5EPSS 0.003
CVE-2020-12518
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.
Published 2020-12-17 · Modified
5.5EPSS 0.007