6.5

CVE-2023-46144

A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.

Data is provided by the National Vulnerability Database (NVD)
PhoenixcontactAxc F 1152 Firmware Version <= 2024.0
   PhoenixcontactAxc F 1152 Version-
PhoenixcontactAxc F 2152 Firmware Version <= 2024.0
   PhoenixcontactAxc F 2152 Version-
PhoenixcontactAxc F 3152 Firmware Version <= 2024.0
   PhoenixcontactAxc F 3152 Version-
PhoenixcontactBpc 9102s Firmware Version <= 2024.0
   PhoenixcontactBpc 9102s Version-
PhoenixcontactEpc 1502 Firmware Version <= 2024.0
   PhoenixcontactEpc 1502 Version-
PhoenixcontactEpc 1522 Firmware Version <= 2024.0
   PhoenixcontactEpc 1522 Version-
PhoenixcontactPlcnext Engineer Version <= 2024.0
PhoenixcontactRfc 4072r Firmware Version <= 2024.0
   PhoenixcontactRfc 4072r Version-
PhoenixcontactRfc 4072s Firmware Version <= 2024.0
   PhoenixcontactRfc 4072s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.139
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
info@cert.vde.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-494 Download of Code Without Integrity Check

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.