VendorsPHOENIX CONTACTplcnext_technology_starterkitall versions
Vulnerabilities

PHOENIX CONTACT PLCnext Technology Starterkit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2020-12519
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
Published 2020-12-17 · Modified
10.0EPSS 0.009
CVE-2020-12517
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).
Published 2020-12-17 · Modified
9.0EPSS 0.011
CVE-2021-34570
Phoenix Contact: DoS for PLCnext Control devices in versions prior to 2021.0.5 LTS
Published 2021-09-27 · Modified
7.8EPSS 0.010
CVE-2020-12521
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.
Published 2020-12-17 · Modified
6.5EPSS 0.005
CVE-2020-12518
Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.
Published 2020-12-17 · Modified
5.5EPSS 0.007