CVE-2023-46144: PHOENIX CONTACT: PLCnext Control prone to download of code without integrity check
Published Dec 14, 2023
·Updated
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
Affected Software
17 affected components
All of the following
Phoenixcontact Axc F 1152 Firmware<=2024.0
Phoenixcontact Axc F 1152
All of the following
Phoenixcontact Axc F 2152 Firmware<=2024.0
Phoenixcontact Axc F 2152
All of the following
Phoenixcontact Axc F 3152 Firmware<=2024.0
Phoenixcontact Axc F 3152
All of the following
Phoenixcontact Bpc 9102s Firmware<=2024.0
Phoenixcontact Bpc 9102s
All of the following
Phoenixcontact Epc 1502 Firmware<=2024.0
Phoenixcontact Epc 1502
All of the following
Phoenixcontact Epc 1522 Firmware<=2024.0
Phoenixcontact Epc 1522
Phoenixcontact Plcnext Engineer<=2024.0
All of the following
Phoenixcontact Rfc 4072r Firmware<=2024.0
Phoenixcontact Rfc 4072r
All of the following
Phoenixcontact Rfc 4072s Firmware<=2024.0
Phoenixcontact Rfc 4072s
Event History
Dec 14, 2023
CVE Published
02:08 PM
Data Sourced
02:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46144?
CVE-2023-46144 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-46144?
To mitigate CVE-2023-46144, ensure that firmware updates are downloaded from trusted sources and perform integrity checks.
3
What products are affected by CVE-2023-46144?
CVE-2023-46144 impacts various Phoenix Contact PLCnext products, including the Axc F, EPC, and RFC series.
4
Can CVE-2023-46144 be exploited remotely?
Yes, CVE-2023-46144 can be exploited by remote attackers with low privileges.
5
What is the nature of the vulnerability in CVE-2023-46144?
CVE-2023-46144 involves a lack of integrity checks during code downloads, allowing potential integrity compromise.