Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Phoenixcontact
Subscribe
|
Automationworx Software Suite
Subscribe
Axc 1050
Subscribe
Axc 1050 Firmware
Subscribe
Axc 1050 Xc
Subscribe
Axc 1050 Xc Firmware
Subscribe
Axc 3050
Subscribe
Axc 3050 Firmware
Subscribe
Config\+
Subscribe
Fc 350 Pci Eth
Subscribe
Fc 350 Pci Eth Firmware
Subscribe
Ilc1x0
Subscribe
Ilc1x0 Firmware
Subscribe
Ilc1x1
Subscribe
Ilc1x1 Firmware
Subscribe
Ilc 3xx
Subscribe
Ilc 3xx Firmware
Subscribe
Pc Worx
Subscribe
Pc Worx Express
Subscribe
Pc Worx Rt Basic
Subscribe
Pc Worx Rt Basic Firmware
Subscribe
Pc Worx Srt
Subscribe
Rfc 430 Eth-ib
Subscribe
Rfc 430 Eth-ib Firmware
Subscribe
Rfc 450 Eth-ib
Subscribe
Rfc 450 Eth-ib Firmware
Subscribe
Rfc 460r Pn 3tx
Subscribe
Rfc 460r Pn 3tx Firmware
Subscribe
Rfc 470s Pn 3tx
Subscribe
Rfc 470s Pn 3tx Firmware
Subscribe
Rfc 480s Pn 4tx
Subscribe
Rfc 480s Pn 4tx Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50386 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2023-057/ |
|
History
Thu, 22 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-05-22T17:39:45.716Z
Reserved: 2023-10-17T07:04:03.576Z
Link: CVE-2023-46143
Updated: 2024-08-02T20:37:39.880Z
Status : Modified
Published: 2023-12-14T14:15:43.207
Modified: 2024-11-21T08:27:58.220
Link: CVE-2023-46143
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD