8.8
CVE-2023-46142
- EPSS 0.26%
- Veröffentlicht 14.12.2023 14:15:42
- Zuletzt bearbeitet 21.11.2024 08:27:58
- Quelle info@cert.vde.com
- Teams Watchlist Login
- Unerledigt Login
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact ≫ Axc F 1152 Firmware Version <= 2024.0
Phoenixcontact ≫ Axc F 2152 Firmware Version <= 2024.0
Phoenixcontact ≫ Axc F 3152 Firmware Version <= 2024.0
Phoenixcontact ≫ Bpc 9102s Firmware Version <= 2024.0
Phoenixcontact ≫ Epc 1502 Firmware Version <= 2024.0
Phoenixcontact ≫ Epc 1522 Firmware Version <= 2024.0
Phoenixcontact ≫ Plcnext Engineer Version <= 2024.0
Phoenixcontact ≫ Rfc 4072r Firmware Version <= 2024.0
Phoenixcontact ≫ Rfc 4072s Firmware Version <= 2024.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.26% | 0.49 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
info@cert.vde.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.