Phoenixcontact Phoenixcontact

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Phoenixcontact product.

RSS Feeds for Phoenixcontact security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Phoenixcontact products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Phoenixcontact Sorted by Most Security Vulnerabilities since 2018

Phoenixcontact Charx Sec 315020 vulnerabilities

Phoenixcontact Charx Sec 310020 vulnerabilities

Phoenixcontact Charx Sec 305020 vulnerabilities

Phoenixcontact Charx Sec 300020 vulnerabilities

Phoenixcontact Rfc 4072s2 vulnerabilities

Phoenixcontact Rfc 4072r2 vulnerabilities

Phoenixcontact Axc F 11522 vulnerabilities

Phoenixcontact Axc F 12522 vulnerabilities

Phoenixcontact Axc F 2000 Ea2 vulnerabilities

Phoenixcontact Axc F 21522 vulnerabilities

Phoenixcontact Axc F 31522 vulnerabilities

Phoenixcontact Bpc 9102s2 vulnerabilities

Phoenixcontact Epc 15222 vulnerabilities

Phoenixcontact Iol Conf1 vulnerability

By the Year

In 2026 there have been 23 vulnerabilities in Phoenixcontact with an average score of 8.2 out of ten. Phoenixcontact did not have any published security vulnerabilities last year. That is, 23 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 23 8.20
2025 0 0.00
2024 0 0.00
2023 8 8.56
2022 4 8.23
2021 2 7.40
2020 4 7.80
2019 4 7.80

It may take a day or so for new Phoenixcontact vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Phoenixcontact Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-7849 Jul 30, 2026
Cmd Injection via Special Elements in System Config Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44108 Jul 30, 2026
Premature Firewall Shutdown Exposes Services Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44107 Jul 30, 2026
CharxModbusServer Unauth Reboot via Modbus TCP DoS A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44105 Jul 30, 2026
Local user credentials leaked via logs enabling SSH login as user-app The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44106 Jul 30, 2026
Priv Esc via User-App init-script A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44104 Jul 30, 2026
Firmware Update in Charging Controller Lacks Signature (CVE-202644104) The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44103 Jul 30, 2026
Unauthenticated Firmware Injection via JupiCore Service (CVE-2026-44103) An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44102 Jul 30, 2026
Unauthenticated OCPP Backend Remote Firmware Download Vulnerability An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44101 Jul 30, 2026
Unauthenticated reconfig of CHARX OCPP Agent leads to DoS & Data Disclosure Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44100 Jul 30, 2026
Unauth Remote Reconfig Attack on CHARX JupiCore Charging Service The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44099 Jul 30, 2026
Local Privilege Escalation: User to Root via System Config A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44098 Jul 30, 2026
OS Cmd Injection in OCPP Backend via firewallbypass This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44097 Jul 30, 2026
IoT REST Firmware Upload Flaw: Arbitrary File Persistence A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44096 Jul 30, 2026
Privilege Escalation in udhcpc, local charx-web execs as root A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44095 Jul 30, 2026
Priv Esc via Network Config Script on Linux A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44094 Jul 30, 2026
Firmware Partition Default Credentials Allow Unprivileged SSH Access An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44093 Jul 30, 2026
Local Priv. Escalation via init-script in systemd (CVE-2026-44093) A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44092 Jul 30, 2026
Unauthenticated Input Injection in ModbusServer via MQTT (CVE-2026-44092) An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44091 Jul 30, 2026
Unauthenticated ID Injection in MQTT Broker Creates Config Entry An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-44090 Jul 30, 2026
Unauthenticated Access to MQTT Broker (CVE-2026-44090) Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.
Charx Sec 3150
Charx Sec 3100
Charx Sec 3050
And others...
CVE-2026-41032 Jun 03, 2026
Unauthenticated Adjacent Log File Disclosure in Controller It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
Charx Sec 3150 Firmware
Charx Sec 3100 Firmware
Charx Sec 3050 Firmware
And others...
CVE-2025-41669 May 27, 2026
PLCnext Control Arbitrary Code Execution via Unverified APP Install The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.
Axc F 1152
Axc F 1252
Axc F 2000 Ea
And others...
CVE-2025-41670 May 27, 2026
Privileged Service LPE via User-Writable Config (CVE-2025-41670) A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successful exploitation may result in a local privilege escalation.
Axc F 1152
Axc F 1252
Axc F 2000 Ea
And others...
CVE-2023-46143 Dec 14, 2023
CVE-2023-46143: Remote PLC Mod via Missing Integrity Check Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
Automationworx Software Suite
Config
Pc Worx
And others...
CVE-2023-0757 Dec 14, 2023
PHOENIX CONTACT ProConOS eCLR Unauth Remote Code Upload Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.
Multiprog
Proconos Eclr
CVE-2023-46141 Dec 14, 2023
PHOENIX CONTACT Classic line: Permission flaw grants remote full access Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
Automationworx Software Suite
Config
Pc Worx
And others...
CVE-2023-46142 Dec 14, 2023
PLCnext PLCs: Permission Misassignment Lets Full Access A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
Plcnext Engineer
CVE-2023-46144 Dec 14, 2023
PLCnext Integrity Check Omission Allows Remote Low-Privileged Exploitation A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
Plcnext Engineer
CVE-2023-5592 Dec 14, 2023
Unauthenticated Remote Download w/o Integrity Check in PHOENIX MULTIPROG Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.
Multiprog
Proconos Eclr
CVE-2023-3935 Sep 13, 2023
CodeMeter Runtime <=7.60b Heap Buffer Overflow RCE A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
Module Type Package Designer
Activation Wizard
Plcnext Engineer
And others...
CVE-2023-1109 Apr 17, 2023
File System RCE via URL in Phoenix Contacts ENERGY AXC PU Web Service In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
Energy Axc Pu
CVE-2022-3737 Nov 15, 2022
PHOENIX CONTACT Automationworx 1.89: Buffer Overread In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
Automationworx Software Suite
CVE-2022-3461 Nov 15, 2022
Heap Buffer Overflow in PHOENIX CONTACT Automationworx Suite 1.89 In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
Automationworx Software Suite
CVE-2021-34579 Nov 09, 2022
Unauthenticated access to Apache in Phoenix Contact FL MGUARD DM 1.12/1.13 In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read mGuard configuration profiles (ATV profiles). Such configuration profiles may contain sensitive information, e.g. private keys associated with IPsec VPN connections.
Fl Mguard Dm
CVE-2022-31801 Jun 21, 2022
An unauthenticated An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
Multiprog
Proconos
CVE-2021-34597 Nov 04, 2021
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.
Pc Worx
Pc Worx Express
CVE-2021-33542 Jun 25, 2021
Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities. Automated systems in operation which were programmed with one of the above-mentioned products are not affected.
Config
Pc Worx
Pc Worx Express
And others...
CVE-2020-12497 Jul 01, 2020
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.
Pc Worx
Pc Worx Express
CVE-2020-12498 Jul 01, 2020
mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.
Pc Worx
Pc Worx Express
CVE-2020-10940 Mar 27, 2020
Local Privilege Escalation Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.
Portico Server 16 Client
Portico Server 1 Client
Portico Server 4 Client
And others...
CVE-2020-10939 Mar 27, 2020
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.
Pc Worx Srt
CVE-2019-16675 Oct 31, 2019
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86 An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.
Config
Pc Worx
Pc Worx Express
And others...
CVE-2019-12870 Jun 24, 2019
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86 An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized Pointer and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.
Automationworx Software Suite
CVE-2019-12869 Jun 24, 2019
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86 An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-Of-Bounds Read, Information Disclosure, and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.
Automationworx Software Suite
CVE-2019-12871 Jun 24, 2019
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86 An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to a Use-After-Free and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.
Automationworx Software Suite
CVE-2017-10053 Aug 08, 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D) Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Fl Mguard Dm
CVE-2017-10078 Aug 08, 2017
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting) Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting). The supported version that is affected is Java SE: 8u131. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data as well as unauthorized access to critical data or complete access to all Java SE accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Fl Mguard Dm
CVE-2017-10198 Aug 08, 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security) Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Fl Mguard Dm
CVE-2017-10176 Aug 08, 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security) Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Fl Mguard Dm
CVE-2017-10135 Aug 08, 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE) Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Fl Mguard Dm
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.