PT-2023-7706 · Phoenix Contact · Axc 1050 Xc+17

Reid Wightman

·

Published

2023-12-12

·

Updated

2023-12-21

·

CVE-2023-46141

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Phoenix Contact Automation Worx Software Suite versions (affected versions not specified) AXC 1050 versions (affected versions not specified) AXC 1050 XC versions (affected versions not specified) AXC 3050 versions (affected versions not specified) Config+ versions (affected versions not specified) FC 350 PCI ETH versions (affected versions not specified) ILC1x0 versions (affected versions not specified) ILC1x1 versions (affected versions not specified) ILC 3xx versions (affected versions not specified) PC Worx versions (affected versions not specified) PC Worx Express versions (affected versions not specified) PC WORX RT BASIC versions (affected versions not specified) PC WORX SRT versions (affected versions not specified) RFC 430 ETH-IB versions (affected versions not specified) RFC 450 ETH-IB versions (affected versions not specified) RFC 460R PN 3TX versions (affected versions not specified) RFC 470S PN 3TX versions (affected versions not specified) RFC 480S PN 4TX versions (affected versions not specified)
Description The issue is related to an incorrect permission assignment for a critical resource, which can be exploited by a remote attacker to gain full access to the device. This can be achieved by loading a specially crafted project file. The vulnerability affects multiple products of the PHOENIX CONTACT classic line.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2023-08773
CVE-2023-46141

Affected Products

Axc 1050
Axc 1050 Xc
Axc 3050
Config+
Fc 350 Pci Eth
Ilc 3Xx
Ilc1X0
Ilc1X1
Pc Worx Rt Basic
Pc Worx Srt
Pc Worx
Pc Worx Express
Phoenix Contact Automation Worx Software Suite
Rfc 430 Eth-Ib
Rfc 450 Eth-Ib
Rfc 460R Pn 3Tx
Rfc 470S Pn 3Tx
Rfc 480S Pn 4Tx