CVE-2023-46142
14.12.2023, 14:15
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.Enginsight
| Vendor | Product | Version |
|---|---|---|
| phoenixcontact | axc_f_1152_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | axc_f_2152_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | axc_f_3152_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | bpc_9102s_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | epc_1502_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | epc_1522_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | plcnext_engineer | 𝑥 ≤ 2024.0 |
| phoenixcontact | rfc_4072r_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | rfc_4072s_firmware | 𝑥 ≤ 2024.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration