VendorsPHOENIX CONTACTpc_worxall versions
Vulnerabilities

PHOENIX CONTACT PC WORX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-46141
Phoenix Contact: Automation Worx and classic line controllers prone to Incorrect Permission Assignment for Critical Resource
Published 2023-12-14 · Modified
9.8EPSS 0.009
CVE-2020-12497
Phoenix Contact Automation Worx <= 1.87: stack-based overflow
Published 2020-07-01 · Modified
7.8EPSS 0.147
CVE-2019-16675
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.
Published 2019-10-31 · Modified
7.8EPSS 0.033
CVE-2020-12498
Phoenix Contact Automation Worx <= 1.87: out-of-bounds read remote code execution
Published 2020-07-01 · Modified
7.8EPSS 0.021
CVE-2021-33542
Phoenix Contact: Automation Worx Software Suite affected by Remote Code Execution (RCE) vulnerability
Published 2021-06-25 · Modified
7.8EPSS 0.018
CVE-2021-34597
Phoenix Contact: PC Worx/-Express prone to improper input validation vulnerability
Published 2021-11-04 · Modified
7.8EPSS 0.007
CVE-2023-46143
Phoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLC
Published 2023-12-14 · Modified
7.5EPSS 0.003