CVE-2023-46143

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2023-057/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:phoenixcontact:automationworx_software_suite:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:phoenixcontact:axc_1050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_1050:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:phoenixcontact:axc_1050_xc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_1050_xc:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:phoenixcontact:axc_3050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_3050:-:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:a:phoenixcontact:config\+:*:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:phoenixcontact:fc_350_pci_eth_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:fc_350_pci_eth:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:phoenixcontact:ilc1x0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:ilc1x0:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:phoenixcontact:ilc1x1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:ilc1x1:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:phoenixcontact:ilc_3xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:ilc_3xx:-:*:*:*:*:*:*:*

Configuration 10 (hide)

cpe:2.3:a:phoenixcontact:pc_worx:*:*:*:*:*:*:*:*

Configuration 11 (hide)

cpe:2.3:a:phoenixcontact:pc_worx_express:*:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:phoenixcontact:pc_worx_rt_basic_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:pc_worx_rt_basic:-:*:*:*:*:*:*:*

Configuration 13 (hide)

cpe:2.3:a:phoenixcontact:pc_worx_srt:*:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:phoenixcontact:rfc_430_eth-ib_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_430_eth-ib:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:phoenixcontact:rfc_450_eth-ib_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_450_eth-ib:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:phoenixcontact:rfc_460r_pn_3tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_460r_pn_3tx:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:phoenixcontact:rfc_470s_pn_3tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_470s_pn_3tx:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:phoenixcontact:rfc_480s_pn_4tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_480s_pn_4tx:-:*:*:*:*:*:*:*

History

21 Dec 2023, 17:15

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2023-057/ - () https://cert.vde.com/en/advisories/VDE-2023-057/ - Third Party Advisory
CPE cpe:2.3:a:phoenixcontact:pc_worx_express:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:rfc_460r_pn_3tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:pc_worx_rt_basic:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_430_eth-ib:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:ilc1x1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:rfc_480s_pn_4tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axc_1050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:fc_350_pci_eth_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_3050:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_1050_xc:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:rfc_430_eth-ib_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenixcontact:pc_worx_srt:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axc_3050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:axc_1050_xc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:ilc1x1:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:axc_1050:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:fc_350_pci_eth:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:rfc_470s_pn_3tx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:ilc_3xx:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_470s_pn_3tx:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:rfc_450_eth-ib_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_450_eth-ib:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_460r_pn_3tx:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:pc_worx_rt_basic_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:ilc1x0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:ilc_3xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:ilc1x0:-:*:*:*:*:*:*:*
cpe:2.3:a:phoenixcontact:automationworx_software_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenixcontact:pc_worx:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenixcontact:config\+:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:rfc_480s_pn_4tx:-:*:*:*:*:*:*:*
First Time Phoenixcontact rfc 450 Eth-ib
Phoenixcontact ilc1x0
Phoenixcontact rfc 430 Eth-ib
Phoenixcontact
Phoenixcontact axc 1050
Phoenixcontact ilc 3xx
Phoenixcontact ilc1x0 Firmware
Phoenixcontact rfc 470s Pn 3tx Firmware
Phoenixcontact pc Worx Rt Basic
Phoenixcontact ilc1x1 Firmware
Phoenixcontact axc 3050
Phoenixcontact axc 1050 Xc
Phoenixcontact config\+
Phoenixcontact ilc 3xx Firmware
Phoenixcontact rfc 480s Pn 4tx Firmware
Phoenixcontact rfc 460r Pn 3tx Firmware
Phoenixcontact rfc 450 Eth-ib Firmware
Phoenixcontact rfc 480s Pn 4tx
Phoenixcontact automationworx Software Suite
Phoenixcontact fc 350 Pci Eth
Phoenixcontact rfc 430 Eth-ib Firmware
Phoenixcontact rfc 470s Pn 3tx
Phoenixcontact axc 1050 Xc Firmware
Phoenixcontact pc Worx Srt
Phoenixcontact pc Worx Rt Basic Firmware
Phoenixcontact axc 1050 Firmware
Phoenixcontact ilc1x1
Phoenixcontact axc 3050 Firmware
Phoenixcontact pc Worx
Phoenixcontact rfc 460r Pn 3tx
Phoenixcontact fc 350 Pci Eth Firmware
Phoenixcontact pc Worx Express

14 Dec 2023, 14:49

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-14 14:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-46143

Mitre link : CVE-2023-46143

CVE.ORG link : CVE-2023-46143


JSON object : View

Products Affected

phoenixcontact

  • ilc_3xx
  • axc_1050_xc_firmware
  • rfc_470s_pn_3tx_firmware
  • rfc_450_eth-ib_firmware
  • axc_1050
  • pc_worx
  • ilc1x0_firmware
  • axc_3050_firmware
  • rfc_470s_pn_3tx
  • rfc_430_eth-ib
  • rfc_460r_pn_3tx_firmware
  • ilc1x1
  • rfc_450_eth-ib
  • rfc_480s_pn_4tx
  • ilc1x1_firmware
  • rfc_460r_pn_3tx
  • ilc_3xx_firmware
  • pc_worx_srt
  • rfc_480s_pn_4tx_firmware
  • axc_1050_xc
  • fc_350_pci_eth_firmware
  • ilc1x0
  • pc_worx_rt_basic
  • automationworx_software_suite
  • axc_1050_firmware
  • fc_350_pci_eth
  • rfc_430_eth-ib_firmware
  • pc_worx_express
  • axc_3050
  • config\+
  • pc_worx_rt_basic_firmware
CWE
CWE-494

Download of Code Without Integrity Check