A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.

Project Subscriptions

Vendors Products
Phoenixcontact Subscribe
Axc F 1152 Subscribe
Axc F 1152 Firmware Subscribe
Axc F 2152 Subscribe
Axc F 2152 Firmware Subscribe
Axc F 3152 Subscribe
Axc F 3152 Firmware Subscribe
Bpc 9102s Subscribe
Bpc 9102s Firmware Subscribe
Epc 1502 Subscribe
Epc 1502 Firmware Subscribe
Epc 1522 Subscribe
Epc 1522 Firmware Subscribe
Plcnext Engineer Subscribe
Rfc 4072r Subscribe
Rfc 4072r Firmware Subscribe
Rfc 4072s Subscribe
Rfc 4072s Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-50387 A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 01 Oct 2024 06:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-10-01T06:18:18.730Z

Reserved: 2023-10-17T07:04:03.577Z

Link: CVE-2023-46144

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-14T14:15:43.447

Modified: 2024-11-21T08:27:58.380

Link: CVE-2023-46144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses