CRITICAL · 9.8

CVE-2023-46141

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affecte...

Vulnerability Description

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
PhoenixcontactAutomationworx Software SuiteAll versions
PhoenixcontactAxc 1050 FirmwareAll versions
PhoenixcontactAxc 1050-
PhoenixcontactAxc 1050 Xc FirmwareAll versions
PhoenixcontactAxc 1050 Xc-
PhoenixcontactAxc 3050 FirmwareAll versions
PhoenixcontactAxc 3050-
PhoenixcontactConfig\+All versions
PhoenixcontactFc 350 Pci Eth FirmwareAll versions
PhoenixcontactFc 350 Pci Eth-
PhoenixcontactIlc1X0 FirmwareAll versions
PhoenixcontactIlc1X0-
PhoenixcontactIlc1X1 FirmwareAll versions
PhoenixcontactIlc1X1-
PhoenixcontactIlc 3Xx FirmwareAll versions
PhoenixcontactIlc 3Xx-
PhoenixcontactPc WorxAll versions
PhoenixcontactPc Worx ExpressAll versions
PhoenixcontactPc Worx Rt Basic FirmwareAll versions
PhoenixcontactPc Worx Rt Basic-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-46141?

CVE-2023-46141 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affecte...

How severe is CVE-2023-46141?

CVE-2023-46141 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-46141?

Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Automationworx Software Suite, Phoenixcontact Axc 1050 Firmware, Phoenixcontact Axc 1050, Phoenixcontact Axc 1050 Xc Firmware, Phoenixcontact Axc 1050 Xc.