Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
La vulnerabilidad de descarga de código sin verificación de integridad en los PLC de la línea clásica de PHOENIX CONTACT permite que un atacante remoto no autenticado modifique algunas o todas las aplicaciones en un PLC.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | HIGH |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-494
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| phoenixcontact | automationworx_software_suite | * | <built-in method update of dict object at 0x7fd36939cc40> | Application |
| phoenixcontact | axc_1050_firmware | * | <built-in method update of dict object at 0x7fd36939f740> | Operating System |
| phoenixcontact | axc_1050_xc_firmware | * | <built-in method update of dict object at 0x7fd36b258080> | Operating System |
| phoenixcontact | axc_3050_firmware | * | <built-in method update of dict object at 0x7fd36b2e1a40> | Operating System |
| phoenixcontact | config\+ | * | <built-in method update of dict object at 0x7fd36939c500> | Application |
| phoenixcontact | fc_350_pci_eth_firmware | * | <built-in method update of dict object at 0x7fd36939d700> | Operating System |
| phoenixcontact | ilc1x0_firmware | * | <built-in method update of dict object at 0x7fd2dbda9340> | Operating System |
| phoenixcontact | ilc1x1_firmware | * | <built-in method update of dict object at 0x7fd2dbda9f00> | Operating System |
| phoenixcontact | ilc_3xx_firmware | * | <built-in method update of dict object at 0x7fd36b2593c0> | Operating System |
| phoenixcontact | pc_worx | * | <built-in method update of dict object at 0x7fd36939d380> | Application |
| phoenixcontact | pc_worx_express | * | <built-in method update of dict object at 0x7fd36939c980> | Application |
| phoenixcontact | pc_worx_rt_basic_firmware | * | <built-in method update of dict object at 0x7fd36939cec0> | Operating System |
| phoenixcontact | pc_worx_srt | * | <built-in method update of dict object at 0x7fd368d56300> | Application |
| phoenixcontact | rfc_430_eth-ib_firmware | * | <built-in method update of dict object at 0x7fd341e2b540> | Operating System |
| phoenixcontact | rfc_450_eth-ib_firmware | * | <built-in method update of dict object at 0x7fd2dbda8780> | Operating System |
| phoenixcontact | rfc_460r_pn_3tx_firmware | * | <built-in method update of dict object at 0x7fd36b2e04c0> | Operating System |
| phoenixcontact | rfc_470s_pn_3tx_firmware | * | <built-in method update of dict object at 0x7fd36939c100> | Operating System |
| phoenixcontact | rfc_480s_pn_4tx_firmware | * | <built-in method update of dict object at 0x7fd2dbdaacc0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:phoenixcontact:automationworx_software_suite:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:axc_1050_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:axc_1050:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:axc_1050_xc_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:axc_1050_xc:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:axc_3050_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:axc_3050:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:phoenixcontact:config\+:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:fc_350_pci_eth_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:fc_350_pci_eth:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:ilc1x0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:ilc1x0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:ilc1x1_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:ilc1x1:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:ilc_3xx_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:ilc_3xx:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:phoenixcontact:pc_worx:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:phoenixcontact:pc_worx_express:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:pc_worx_rt_basic_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:pc_worx_rt_basic:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:phoenixcontact:pc_worx_srt:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:rfc_430_eth-ib_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:rfc_430_eth-ib:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:rfc_450_eth-ib_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:rfc_450_eth-ib:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:rfc_460r_pn_3tx_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:rfc_460r_pn_3tx:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:rfc_470s_pn_3tx_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:rfc_470s_pn_3tx:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:phoenixcontact:rfc_480s_pn_4tx_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:phoenixcontact:rfc_480s_pn_4tx:-:*:*:*:*:*:*:* |