Description
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
Published: 2023-12-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-50386 Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
History

Thu, 22 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Phoenixcontact Automationworx Software Suite Axc 1050 Axc 1050 Firmware Axc 1050 Xc Axc 1050 Xc Firmware Axc 3050 Axc 3050 Firmware Config\+ Fc 350 Pci Eth Fc 350 Pci Eth Firmware Ilc1x0 Ilc1x0 Firmware Ilc1x1 Ilc1x1 Firmware Ilc 3xx Ilc 3xx Firmware Pc Worx Pc Worx Express Pc Worx Rt Basic Pc Worx Rt Basic Firmware Pc Worx Srt Rfc 430 Eth-ib Rfc 430 Eth-ib Firmware Rfc 450 Eth-ib Rfc 450 Eth-ib Firmware Rfc 460r Pn 3tx Rfc 460r Pn 3tx Firmware Rfc 470s Pn 3tx Rfc 470s Pn 3tx Firmware Rfc 480s Pn 4tx Rfc 480s Pn 4tx Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2025-05-22T17:39:45.716Z

Reserved: 2023-10-17T07:04:03.576Z

Link: CVE-2023-46143

cve-icon Vulnrichment

Updated: 2024-08-02T20:37:39.880Z

cve-icon NVD

Status : Modified

Published: 2023-12-14T14:15:43.207

Modified: 2024-11-21T08:27:58.220

Link: CVE-2023-46143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses