VulnerabilityModified
CVE-2023-46144
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
MEDIUM 6.5EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-494
- Affected
- phoenixcontact/axc f 1152 firmware · phoenixcontact/axc f 2152 firmware · phoenixcontact/axc f 3152 firmware · phoenixcontact/bpc 9102s firmware · phoenixcontact/epc 1502 firmware · phoenixcontact/epc 1522 firmware · phoenixcontact/plcnext engineer · phoenixcontact/rfc 4072r firmware · phoenixcontact/rfc 4072s firmware
- Source
- info@cert.vde.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.