8.8

CVE-2023-46142

A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhoenixcontactAxc F 1152 Firmware Version <= 2024.0
   PhoenixcontactAxc F 1152 Version-
PhoenixcontactAxc F 2152 Firmware Version <= 2024.0
   PhoenixcontactAxc F 2152 Version-
PhoenixcontactAxc F 3152 Firmware Version <= 2024.0
   PhoenixcontactAxc F 3152 Version-
PhoenixcontactBpc 9102s Firmware Version <= 2024.0
   PhoenixcontactBpc 9102s Version-
PhoenixcontactEpc 1502 Firmware Version <= 2024.0
   PhoenixcontactEpc 1502 Version-
PhoenixcontactEpc 1522 Firmware Version <= 2024.0
   PhoenixcontactEpc 1522 Version-
PhoenixcontactPlcnext Engineer Version <= 2024.0
PhoenixcontactRfc 4072r Firmware Version <= 2024.0
   PhoenixcontactRfc 4072r Version-
PhoenixcontactRfc 4072s Firmware Version <= 2024.0
   PhoenixcontactRfc 4072s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.49
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.