First published: Thu Dec 14 2023(Updated: )
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Phoenix Contact Axc F 1152 | <=2024.0 | |
Phoenix Contact Axc F 1152 | ||
All of | ||
Phoenix Contact Axioline F AXL F 2152 Firmware | <=2024.0 | |
Phoenix Contact Axioline F AXL F 2152 Firmware | ||
All of | ||
Phoenix Contact AXC F 3152 Firmware | <=2024.0 | |
Phoenix Contact AXC F 3152 Firmware | ||
All of | ||
Phoenix Contact BPC 9102S Firmware | <=2024.0 | |
Phoenix Contact BPC 9102S Firmware | ||
All of | ||
Phoenix Contact EPC 1502 Firmware | <=2024.0 | |
Phoenix Contact EPC 1502 Firmware | ||
All of | ||
Phoenix Contact EPC 1522 Firmware | <=2024.0 | |
Phoenix Contact EPC 1522 Firmware | ||
Phoenix Contact PLCnext Engineer | <=2024.0 | |
All of | ||
Phoenix Contact RFC 4072R Firmware | <=2024.0 | |
phoenixcontact rfc 4072r firmware | ||
All of | ||
Phoenix Contact RFC 4072S | <=2024.0 | |
Phoenix Contact RFC 4072S |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46142 is considered a critical vulnerability due to its potential to allow unauthorized remote access to affected devices.
To fix CVE-2023-46142, update the firmware of the affected Phoenix Contact devices to the latest version released after 2024.0.
The affected devices include Phoenix Contact AXC F 1152, AXC F 2152, AXC F 3152, BPC 9102S, EPC 1502, EPC 1522, RFC 4072R, and RFC 4072S firmware versions up to 2024.0.
CVE-2023-46142 allows remote attackers with low privileges to gain full access to the affected devices, potentially compromising system integrity.
As of now, there have been no specific exploits publicly disclosed for CVE-2023-46142, but the vulnerability's nature poses a significant risk.