Phoenix Contact's vulnerability profile spans a large portfolio of industrial automation and control systems, particularly its CHARX secure remote-access appliances and related firmware, which represent critical infrastructure for manufacturing and utility environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the high-stakes operational context of devices deployed to protect and mediate access to production networks. The exposure recurs across the CHARX product lines and centers on input-handling and command-injection weakness classes—including improper neutralization of web input, OS command injection, and insufficient validation—that are characteristic of industrial control interfaces where parsing and privilege boundaries must be precisely enforced. Defenders should prioritize patches for internet-exposed CHARX appliances and treat this vendor's advisories as high-impact for OT and critical infrastructure; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phoenixcontact over time
Signals from CVEs in this vendor scope (156 CVEs).
156 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2016-8371HIGH The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled. | Apr 5, 2018 | 7.3 | 35 | NO | YES |
CVE-2018-13990CRITICAL The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Att | May 6, 2019 | 9.8 | 32 | NO | NO |
CVE-2016-8380HIGH The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication. | Apr 5, 2018 | 7.3 | 32 | NO | YES |
CVE-2025-25270CRITICAL An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations. | Jul 8, 2025 | 9.8 | 31 | NO | NO |
CVE-2024-43384HIGH A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer. | May 7, 2026 | 8.0 | 30 | NO | NO |
CVE-2023-0757CRITICAL Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to u | Dec 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-3935CRITICAL A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of | Sep 13, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-31800CRITICAL An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device. | Jun 21, 2022 | 9.8 | 30 | NO | NO |
CVE-2018-13992CRITICAL The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default. | May 7, 2019 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (156 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phoenixcontact.
Media articles that mention a CVE ID that affects a product developed by Phoenixcontact — matched by CVE ID, not by vendor name.