ZeroHour

CVE-2023-46144

CVSS 3.1
6.5 medium
EPSS
<1%p24
Published
()
Modified
Description

A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.

Vendors
phoenixcontact
Products
axc f 1152 firmware, axc f 2152 firmware, axc f 3152 firmware, bpc 9102s firmware, epc 1502 firmware, epc 1522 firmware, plcnext engineer, rfc 4072r firmware, rfc 4072s firmware
Weakness
CWE-494
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.