CVE-2023-46144

A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:phoenixcontact:axc_f_1152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_f_1152:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:phoenixcontact:axc_f_2152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_f_2152:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:phoenixcontact:axc_f_3152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_f_3152:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:phoenixcontact:bpc_9102s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:bpc_9102s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phoenixcontact:epc_1502_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:epc_1502:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:phoenixcontact:epc_1522_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:epc_1522:-:*:*:*:*:*:*:*

Configuration 7 (hide)

cpe:2.3:a:phoenixcontact:plcnext_engineer:*:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:phoenixcontact:rfc_4072r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_4072r:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:phoenixcontact:rfc_4072s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_4072s:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-12-14 14:15

Updated : 2023-12-21 17:16


NVD link : CVE-2023-46144

Mitre link : CVE-2023-46144

CVE.ORG link : CVE-2023-46144


JSON object : View

Products Affected

phoenixcontact

  • axc_f_3152
  • bpc_9102s_firmware
  • epc_1502
  • rfc_4072s
  • rfc_4072s_firmware
  • axc_f_2152_firmware
  • bpc_9102s
  • axc_f_2152
  • axc_f_3152_firmware
  • axc_f_1152_firmware
  • rfc_4072r
  • plcnext_engineer
  • epc_1502_firmware
  • epc_1522_firmware
  • rfc_4072r_firmware
  • axc_f_1152
  • epc_1522
CWE
CWE-494

Download of Code Without Integrity Check