CVE-2023-46141
Published: Dec 14, 2023
Modified: Aug 2, 2024
CVSS v3.1
9.8
Description
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
| Vendor | Product | Versions |
|---|---|---|
PHOENIX CONTACT | Automation Worx Software Suite | affected all |
PHOENIX CONTACT | AXC 1050 | affected all |
PHOENIX CONTACT | AXC 1050 XC | affected all |
PHOENIX CONTACT | AXC 3050 | affected all |
PHOENIX CONTACT | Config+ | affected all |
PHOENIX CONTACT | FC 350 PCI ETH | affected all |
PHOENIX CONTACT | ILC1x0 | affected all |
PHOENIX CONTACT | ILC1x1 | affected all |
PHOENIX CONTACT | ILC 3xx | affected all |
PHOENIX CONTACT | PC Worx | affected all |
PHOENIX CONTACT | PC Worx Express | affected all |
PHOENIX CONTACT | PC WORX RT BASIC | affected all |
PHOENIX CONTACT | PC WORX SRT | affected all |
PHOENIX CONTACT | RFC 430 ETH-IB | affected all |
PHOENIX CONTACT | RFC 450 ETH-IB | affected all |
PHOENIX CONTACT | RFC 460R PN 3TX | affected all |
PHOENIX CONTACT | RFC 470S PN 3TX | affected all |
PHOENIX CONTACT | RFC 480S PN 4TX | affected all |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now