CVE-2023-46143

CWE-4943 documents3 sources
Severity
7.5HIGH
EPSS
0.2%
top 52.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14

Description

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages18 packages

🔴Vulnerability Details

2
GHSA
GHSA-frfw-grgg-284c: Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some o2023-12-14
CVEList
Phoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLC2023-12-14
CVE-2023-46143 (HIGH CVSS 7.5) | Download of Code Without Integrity | cvebase.io