CVE-2023-46143

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CERTVDECNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
phoenixcontactautomationworx_software_suite
*
phoenixcontactaxc_1050_firmware
*
phoenixcontactaxc_1050_xc_firmware
*
phoenixcontactaxc_3050_firmware
*
phoenixcontactconfig\+
*
phoenixcontactfc_350_pci_eth_firmware
*
phoenixcontactilc1x0_firmware
*
phoenixcontactilc1x1_firmware
*
phoenixcontactilc_3xx_firmware
*
phoenixcontactpc_worx
*
phoenixcontactpc_worx_express
*
phoenixcontactpc_worx_rt_basic_firmware
*
phoenixcontactpc_worx_srt
*
phoenixcontactrfc_430_eth-ib_firmware
*
phoenixcontactrfc_450_eth-ib_firmware
*
phoenixcontactrfc_460r_pn_3tx_firmware
*
phoenixcontactrfc_470s_pn_3tx_firmware
*
phoenixcontactrfc_480s_pn_4tx_firmware
*
𝑥
= Vulnerable software versions