First published: Thu Dec 14 2023(Updated: )
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenix Contact Automationworx | ||
All of | ||
Phoenix Contact Axc 1050 Firmware | ||
Phoenix Contact Axc 1050 Firmware | ||
All of | ||
Phoenix Contact Axc 1050 XC Firmware | ||
Phoenix Contact Axc 1050 XC Firmware | ||
All of | ||
Phoenix Contact AXC 3050 | ||
Phoenix Contact AXC 3050 | ||
Phoenix Contact Config+ | ||
All of | ||
Phoenix Contact FC 350 PCI ETH Firmware | ||
Phoenix Contact FC 350 PCI ETH Firmware | ||
All of | ||
Phoenix Contact ILC 1x0 Firmware | ||
Phoenix Contact ILC 1x0 Firmware | ||
All of | ||
Phoenix Contact ILC 1x1 GSM/GPRS Firmware | ||
Phoenix Contact ILC 1x1 GSM/GPRS Firmware | ||
All of | ||
Phoenix Contact ILC 3xx | ||
Phoenix Contact ILC 3xx | ||
Phoenix Contact PC Worx | ||
Phoenix Contact PC Worx Express | ||
All of | ||
Phoenix Contact PC Worx RT Basic | ||
Phoenix Contact PC Worx RT Basic | ||
Phoenix Contact PC Worx SRT | ||
All of | ||
Phoenix Contact RFC 430 ETH-IB | ||
Phoenix Contact RFC 430 ETH-IB | ||
All of | ||
Phoenix Contact RFC 450 ETH-IB Firmware | ||
Phoenix Contact RFC 450 ETH-IB Firmware | ||
All of | ||
Phoenix Contact RFC 460R PN 3TX | ||
Phoenix Contact RFC 460R PN 3TX | ||
All of | ||
Phoenix Contact RFC 470S PN 3TX Firmware | ||
phoenixcontact rfc 470s pn 3tx firmware | ||
All of | ||
Phoenix Contact RFC 480S PN 4TX Firmware | ||
Phoenix Contact RFC 480S PN 4TX Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46143 is considered a high severity vulnerability due to the potential for unauthorized modification of applications on affected PLCs.
To fix CVE-2023-46143, ensure that you apply the latest firmware updates provided by Phoenix Contact for the affected devices.
CVE-2023-46143 affects various Phoenix Contact automation systems including the Automationworx software suite and several PLC firmware versions.
The vulnerability could allow an unauthenticated remote attacker to modify applications on a PLC, potentially leading to system malfunctions or unauthorized access.
Yes, CVE-2023-46143 can be exploited remotely by an unauthenticated attacker.