SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-46144

A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.

MEDIUM 6.5EPSS 0.31%

Does this matter?

Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.

Description

A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.31% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-494
Affected
phoenixcontact/axc f 1152 firmware · phoenixcontact/axc f 2152 firmware · phoenixcontact/axc f 3152 firmware · phoenixcontact/bpc 9102s firmware · phoenixcontact/epc 1502 firmware · phoenixcontact/epc 1522 firmware · phoenixcontact/plcnext engineer · phoenixcontact/rfc 4072r firmware · phoenixcontact/rfc 4072s firmware
Source
info@cert.vde.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.