This page lists publicly disclosed CVE vulnerabilities affecting phoenixcontact multiprog (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-5592 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity. | [email protected] | 7.5 | 0.33% | 2023-12-14 | 2026-06-17 |
| CVE-2023-0757 | Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device. | [email protected] | 9.8 | 0.88% | 2023-12-14 | 2026-06-17 |
| CVE-2022-31801 | An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device. | [email protected] | 9.8 | 1.03% | 2022-06-21 | 2026-06-17 |