CVE-2023-46144
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD (Secondary)
Description
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
Affected (9)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc F 1152 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc F 2152 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Axc F 3152 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Bpc 9102s | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Epc 1502 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Epc 1522 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Rfc 4072r | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2024.0 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Rfc 4072s | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Timeline
No history available yet.