Config
Vendor:
First CVE: Oct 31, 2019 · Active for 6 years
4
Total CVEs
More Total CVEs than 72% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Config over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2019
6 years ago
Most Recent CVE
Dec 14, 2023
955 days ago
CVE Severity & Scoring
Config4 CVEs
75%
25%
All CVEs352,719 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local2 (50.0%)
Network2 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High1 (25.0%)
Unknown0 (0.0%)
User Interaction
None2 (50.0%)
Unknown0 (0.0%)
Required2 (50.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46141CRITICAL Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full a | Dec 14, 2023 | 9.8 | 25 | NO | NO |
CVE-2019-16675HIGH An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to | Oct 31, 2019 | 7.8 | 24 | NO | NO |
CVE-2021-33542HIGH Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could | Jun 25, 2021 | 7.0 | 22 | NO | NO |
CVE-2023-46143HIGH Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. | Dec 14, 2023 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Config
Top CWEs
Versions
No cataloged versions.