First published: Thu Dec 14 2023(Updated: )
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenix Contact Automationworx | ||
All of | ||
Phoenix Contact Axc 1050 Firmware | ||
Phoenix Contact Axc 1050 Firmware | ||
All of | ||
Phoenix Contact Axc 1050 XC Firmware | ||
Phoenix Contact Axc 1050 XC Firmware | ||
All of | ||
Phoenix Contact AXC 3050 | ||
Phoenix Contact AXC 3050 | ||
Phoenix Contact Config+ | ||
All of | ||
Phoenix Contact FC 350 PCI ETH Firmware | ||
Phoenix Contact FC 350 PCI ETH Firmware | ||
All of | ||
Phoenix Contact ILC 1x0 Firmware | ||
Phoenix Contact ILC 1x0 Firmware | ||
All of | ||
Phoenix Contact ILC 1x1 GSM/GPRS Firmware | ||
Phoenix Contact ILC 1x1 GSM/GPRS Firmware | ||
All of | ||
Phoenix Contact ILC 3xx | ||
Phoenix Contact ILC 3xx | ||
Phoenix Contact PC Worx | ||
Phoenix Contact PC Worx Express | ||
All of | ||
Phoenix Contact PC Worx RT Basic | ||
Phoenix Contact PC Worx RT Basic | ||
Phoenix Contact PC Worx SRT | ||
All of | ||
Phoenix Contact RFC 430 ETH-IB | ||
Phoenix Contact RFC 430 ETH-IB | ||
All of | ||
Phoenix Contact RFC 450 ETH-IB Firmware | ||
Phoenix Contact RFC 450 ETH-IB Firmware | ||
All of | ||
Phoenix Contact RFC 460R PN 3TX | ||
Phoenix Contact RFC 460R PN 3TX | ||
All of | ||
Phoenix Contact RFC 470S PN 3TX Firmware | ||
phoenixcontact rfc 470s pn 3tx firmware | ||
All of | ||
Phoenix Contact RFC 480S PN 4TX Firmware | ||
Phoenix Contact RFC 480S PN 4TX Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46141 has a high severity rating as it allows a remote unauthenticated attacker to gain full access to the affected devices.
To fix CVE-2023-46141, apply the latest security update provided by Phoenix Contact for the affected products.
CVE-2023-46141 affects multiple products within the Phoenix Contact classic line including Automationworx, Config+, and various firmware versions.
CVE-2023-46141 is categorized as an Incorrect Permission Assignment for Critical Resource vulnerability.
Yes, CVE-2023-46141 can be exploited remotely without authentication, allowing attackers to gain unauthorized access.