phoenix_contact CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

phoenix_contact vulnerability overview

Aggregates CVE and security vulnerability intelligence across all phoenix_contact-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk path handling; exposure may include vendor impact file overwrite in vendor surface production workloads and vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-41032 It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. [email protected] 7.5 0.26% 2026-06-03 2026-06-17
CVE-2025-41670 A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successful exploitation may result in a local privilege escalation. [email protected] 8.7 0.19% 2026-05-27 2026-06-17
CVE-2025-41669 The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control. [email protected] 8.7 0.22% 2026-05-27 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence