CVE-2023-46141
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: info@cert.vde.com (Secondary)
Description
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
Affected (18)
Products: Phoenixcontact: Automationworx Software Suite, Axc 1050 Firmware, Axc 1050 Xc Firmware, Axc 3050 Firmware, Config+, Fc 350 Pci Eth Firmware, Ilc1x0 Firmware, Ilc1x1 Firmware, Ilc 3xx Firmware, Pc Worx, Pc Worx Express, Pc Worx Rt Basic Firmware, Pc Worx Srt, Rfc 430 Eth Ib Firmware, Rfc 450 Eth Ib Firmware, Rfc 460r Pn 3tx Firmware, Rfc 470s Pn 3tx Firmware, Rfc 480s Pn 4tx Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc 1050 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc 1050 Xc | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc 3050 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Fc 350 Pci Eth | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Ilc1x0 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Ilc1x1 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Ilc 3xx | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Pc Worx Rt Basic | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Rfc 430 Eth Ib | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Rfc 450 Eth Ib | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Rfc 460r Pn 3tx | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Rfc 470s Pn 3tx | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Rfc 480s Pn 4tx | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.