CVE-2023-46144
EUVD-2023-5038714.12.2023, 14:15
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| phoenixcontact | axc_f_1152_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | axc_f_2152_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | axc_f_3152_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | bpc_9102s_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | epc_1502_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | epc_1522_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | plcnext_engineer | 𝑥 ≤ 2024.0 |
| phoenixcontact | rfc_4072r_firmware | 𝑥 ≤ 2024.0 |
| phoenixcontact | rfc_4072s_firmware | 𝑥 ≤ 2024.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration