MEDIUM · 6.5

CVE-2023-46144

A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected...

Vulnerability Description

A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
PhoenixcontactAxc F 1152 Firmware<= 2024.0
PhoenixcontactAxc F 1152-
PhoenixcontactAxc F 2152 Firmware<= 2024.0
PhoenixcontactAxc F 2152-
PhoenixcontactAxc F 3152 Firmware<= 2024.0
PhoenixcontactAxc F 3152-
PhoenixcontactBpc 9102S Firmware<= 2024.0
PhoenixcontactBpc 9102S-
PhoenixcontactEpc 1502 Firmware<= 2024.0
PhoenixcontactEpc 1502-
PhoenixcontactEpc 1522 Firmware<= 2024.0
PhoenixcontactEpc 1522-
PhoenixcontactPlcnext Engineer<= 2024.0
PhoenixcontactRfc 4072R Firmware<= 2024.0
PhoenixcontactRfc 4072R-
PhoenixcontactRfc 4072S Firmware<= 2024.0
PhoenixcontactRfc 4072S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-46144?

CVE-2023-46144 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected...

How severe is CVE-2023-46144?

CVE-2023-46144 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-46144?

Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Axc F 1152 Firmware, Phoenixcontact Axc F 1152, Phoenixcontact Axc F 2152 Firmware, Phoenixcontact Axc F 2152, Phoenixcontact Axc F 3152 Firmware.