cbcvebase.
CVE-2023-46143
published 2023-12-14

CVE-2023-46143: Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all…

PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.33%
25.2th percentile
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.

Affected

18 ranges
VendorProductVersion rangeFixed in
phoenix_contactautomation_worx_software_suite
phoenix_contactaxc_1050
phoenix_contactaxc_1050_xc
phoenix_contactaxc_3050
phoenix_contactconfig
phoenix_contactfc_350_pci_eth
phoenix_contactilc1x0
phoenix_contactilc1x1
phoenix_contactilc_3xx
phoenix_contactpc_worx
phoenix_contactpc_worx_express
phoenix_contactpc_worx_rt_basic
phoenix_contactpc_worx_srt
phoenix_contactrfc_430_eth-ib
phoenix_contactrfc_450_eth-ib
phoenix_contactrfc_460r_pn_3tx
phoenix_contactrfc_470s_pn_3tx
phoenix_contactrfc_480s_pn_4tx
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.