CVE-2023-46144
14.12.2023, 14:15
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.Enginsight
Vendor | Product | Version |
---|---|---|
phoenixcontact | axc_f_1152_firmware | 𝑥 ≤ 2024.0 |
phoenixcontact | axc_f_2152_firmware | 𝑥 ≤ 2024.0 |
phoenixcontact | axc_f_3152_firmware | 𝑥 ≤ 2024.0 |
phoenixcontact | bpc_9102s_firmware | 𝑥 ≤ 2024.0 |
phoenixcontact | epc_1502_firmware | 𝑥 ≤ 2024.0 |
phoenixcontact | epc_1522_firmware | 𝑥 ≤ 2024.0 |
phoenixcontact | plcnext_engineer | 𝑥 ≤ 2024.0 |
phoenixcontact | rfc_4072r_firmware | 𝑥 ≤ 2024.0 |
phoenixcontact | rfc_4072s_firmware | 𝑥 ≤ 2024.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration