# CVE-2016-8380

## Summary

- **CVE ID:** CVE-2016-8380
- **Severity:** UNKNOWN
- **CVSS Score:** 0.5
- **CWE:** CWE-767
- **Published:** Apr 5, 2018
- **Last Modified:** Mar 14, 2026

## Description

The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

## Affected Products

- Phoenix Contact — Phoenix Contact ILC PLCs (All ILC 1xx PLCs)

## References

- [CNA](https://ics-cert.us-cert.gov/advisories/ICSA-313-01)
- [CNA](https://www.exploit-db.com/exploits/45590/)
- [CNA](http://www.securityfocus.com/bid/94163)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 12.53%
- **EPSS Percentile:** 93.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._