ZeroHour

CVE-2023-0757

CVSS 3.1
9.8 critical
EPSS
<1%p57
Published
()
Modified
Description

Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.

Vendors
phoenixcontact
Products
multiprog, proconos eclr
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.