IM
IronMonkey Threat Research

CVE-2023-46143 HIGH

Published: 2023-12-14 | Last Modified: 2024-11-21 | Status: Modified

Description

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.

Additional Descriptions (1)

La vulnerabilidad de descarga de código sin verificación de integridad en los PLC de la línea clásica de PHOENIX CONTACT permite que un atacante remoto no autenticado modifique algunas o todas las aplicaciones en un PLC.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Secondary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-494

Affected Products

Vendor Product Version Update Type
phoenixcontact automationworx_software_suite * <built-in method update of dict object at 0x7fd36939cc40> Application
phoenixcontact axc_1050_firmware * <built-in method update of dict object at 0x7fd36939f740> Operating System
phoenixcontact axc_1050_xc_firmware * <built-in method update of dict object at 0x7fd36b258080> Operating System
phoenixcontact axc_3050_firmware * <built-in method update of dict object at 0x7fd36b2e1a40> Operating System
phoenixcontact config\+ * <built-in method update of dict object at 0x7fd36939c500> Application
phoenixcontact fc_350_pci_eth_firmware * <built-in method update of dict object at 0x7fd36939d700> Operating System
phoenixcontact ilc1x0_firmware * <built-in method update of dict object at 0x7fd2dbda9340> Operating System
phoenixcontact ilc1x1_firmware * <built-in method update of dict object at 0x7fd2dbda9f00> Operating System
phoenixcontact ilc_3xx_firmware * <built-in method update of dict object at 0x7fd36b2593c0> Operating System
phoenixcontact pc_worx * <built-in method update of dict object at 0x7fd36939d380> Application
phoenixcontact pc_worx_express * <built-in method update of dict object at 0x7fd36939c980> Application
phoenixcontact pc_worx_rt_basic_firmware * <built-in method update of dict object at 0x7fd36939cec0> Operating System
phoenixcontact pc_worx_srt * <built-in method update of dict object at 0x7fd368d56300> Application
phoenixcontact rfc_430_eth-ib_firmware * <built-in method update of dict object at 0x7fd341e2b540> Operating System
phoenixcontact rfc_450_eth-ib_firmware * <built-in method update of dict object at 0x7fd2dbda8780> Operating System
phoenixcontact rfc_460r_pn_3tx_firmware * <built-in method update of dict object at 0x7fd36b2e04c0> Operating System
phoenixcontact rfc_470s_pn_3tx_firmware * <built-in method update of dict object at 0x7fd36939c100> Operating System
phoenixcontact rfc_480s_pn_4tx_firmware * <built-in method update of dict object at 0x7fd2dbdaacc0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:phoenixcontact:automationworx_software_suite:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:axc_1050_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:axc_1050:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:axc_1050_xc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:axc_1050_xc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:axc_3050_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:axc_3050:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:phoenixcontact:config\+:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:fc_350_pci_eth_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:fc_350_pci_eth:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:ilc1x0_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:ilc1x0:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:ilc1x1_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:ilc1x1:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:ilc_3xx_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:ilc_3xx:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:phoenixcontact:pc_worx:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:phoenixcontact:pc_worx_express:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:pc_worx_rt_basic_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:pc_worx_rt_basic:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:phoenixcontact:pc_worx_srt:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:rfc_430_eth-ib_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:rfc_430_eth-ib:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:rfc_450_eth-ib_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:rfc_450_eth-ib:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:rfc_460r_pn_3tx_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:rfc_460r_pn_3tx:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:rfc_470s_pn_3tx_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:rfc_470s_pn_3tx:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:phoenixcontact:rfc_480s_pn_4tx_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:phoenixcontact:rfc_480s_pn_4tx:-:*:*:*:*:*:*:*

References