SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-46141

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

CRITICAL 9.8EPSS 0.88%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.88% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
phoenixcontact/automationworx software suite · phoenixcontact/axc 1050 firmware · phoenixcontact/axc 1050 xc firmware · phoenixcontact/axc 3050 firmware · phoenixcontact/config\+ · phoenixcontact/fc 350 pci eth firmware · phoenixcontact/ilc1x0 firmware · phoenixcontact/ilc1x1 firmware · phoenixcontact/ilc 3xx firmware · phoenixcontact/pc worx · phoenixcontact/pc worx express · phoenixcontact/pc worx rt basic firmware · phoenixcontact/pc worx srt · phoenixcontact/rfc 430 eth-ib firmware · phoenixcontact/rfc 450 eth-ib firmware · phoenixcontact/rfc 460r pn 3tx firmware · phoenixcontact/rfc 470s pn 3tx firmware · phoenixcontact/rfc 480s pn 4tx firmware
Source
info@cert.vde.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.