TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2023-46141

CRITICAL
9.8

Beschreibung

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht12/14/2023
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

phoenixcontact:automationworx_software_suitephoenixcontact:axc_1050phoenixcontact:axc_1050_firmwarephoenixcontact:axc_1050_xcphoenixcontact:axc_1050_xc_firmwarephoenixcontact:axc_3050phoenixcontact:axc_3050_firmwarephoenixcontact:config\+phoenixcontact:fc_350_pci_ethphoenixcontact:fc_350_pci_eth_firmwarephoenixcontact:ilc1x0phoenixcontact:ilc1x0_firmwarephoenixcontact:ilc1x1phoenixcontact:ilc1x1_firmwarephoenixcontact:ilc_3xxphoenixcontact:ilc_3xx_firmwarephoenixcontact:pc_worxphoenixcontact:pc_worx_expressphoenixcontact:pc_worx_rt_basicphoenixcontact:pc_worx_rt_basic_firmwarephoenixcontact:pc_worx_srtphoenixcontact:rfc_430_eth-ibphoenixcontact:rfc_430_eth-ib_firmwarephoenixcontact:rfc_450_eth-ibphoenixcontact:rfc_450_eth-ib_firmwarephoenixcontact:rfc_460r_pn_3txphoenixcontact:rfc_460r_pn_3tx_firmwarephoenixcontact:rfc_470s_pn_3txphoenixcontact:rfc_470s_pn_3tx_firmwarephoenixcontact:rfc_480s_pn_4txphoenixcontact:rfc_480s_pn_4tx_firmware

Schwachen (CWE)

CWE-732

Referenzen

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.