2023-12-14 15:00:31 +00:00
{
"id" : "CVE-2023-46141" ,
"sourceIdentifier" : "info@cert.vde.com" ,
"published" : "2023-12-14T14:15:42.767" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:27:57.923" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-12-14 15:00:31 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device."
2023-12-21 19:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "La asignaci\u00f3n de permisos incorrecta para una vulnerabilidad de recursos cr\u00edticos en varios productos de la l\u00ednea cl\u00e1sica de PHOENIX CONTACT permite que un atacante remoto no autenticado obtenga acceso completo al dispositivo afectado."
2023-12-14 15:00:31 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "info@cert.vde.com" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
2023-12-14 15:00:31 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-12-14 15:00:31 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "info@cert.vde.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-12-14 15:00:31 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-732"
}
]
}
] ,
2023-12-21 19:00:28 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:phoenixcontact:automationworx_software_suite:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9797B615-825F-4CAA-B36E-5161E37FAF9A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:axc_1050_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F0D586DC-2274-4A32-AE98-7BE174C230CC"
2023-12-21 19:00:28 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:axc_1050:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F55C821-DAA6-4098-BB54-80F6D9ED0CD6"
2023-12-21 19:00:28 +00:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:axc_1050_xc_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "332A6164-CDC1-4DBF-9B62-946EC7D7C4B3"
2023-12-21 19:00:28 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:axc_1050_xc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E03B5234-36FA-4BCE-964D-F55FFFD5CAAC"
2023-12-21 19:00:28 +00:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:axc_3050_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "84066F7B-8306-4743-9F12-75B8F880AD93"
2023-12-21 19:00:28 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:axc_3050:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB9699A2-782D-40F3-B8D6-3C315104BA60"
2023-12-21 19:00:28 +00:00
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:phoenixcontact:config\\+:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A6D8FDB6-6181-49EB-BE6D-236D39A478A1"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:fc_350_pci_eth_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DEB7CA5B-7EEF-4E0E-9A53-83FE28730852"
2023-12-21 19:00:28 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:fc_350_pci_eth:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F4BB6654-41BB-488E-AC8C-E74C05CA198F"
2023-12-21 19:00:28 +00:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:ilc1x0_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5AC07A81-D5D6-449C-93F8-93D6E87487DD"
2023-12-21 19:00:28 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:ilc1x0:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AE45F6AF-7286-48F7-B4BE-AFC948884C7C"
2023-12-21 19:00:28 +00:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:ilc1x1_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8E168AB1-1B81-4990-95E4-56C36275609B"
2023-12-21 19:00:28 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:ilc1x1:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9E318A8B-D1D1-4DD5-AF71-DCBFEFCF2C5E"
2023-12-21 19:00:28 +00:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:ilc_3xx_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "65E1A201-E7B1-452B-8BC6-A355A3BF9460"
2023-12-21 19:00:28 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-12-08 03:06:42 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:ilc_3xx:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FF1C58A6-5220-4509-B426-D1ED5ECFAD05"
2023-12-21 19:00:28 +00:00
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:phoenixcontact:pc_worx:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B975C4E4-83B5-4C98-811B-E6D13687AB85"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:phoenixcontact:pc_worx_express:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE663FFA-4B82-4477-A424-4C9CC83C131E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:pc_worx_rt_basic_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8693B231-3A5C-47B7-BEA5-53D430BBACF4"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:pc_worx_rt_basic:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "08B214FC-776F-454B-8DC4-E7F2E6EFB013"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:phoenixcontact:pc_worx_srt:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A2A6F462-A12F-4E08-9AA6-1C1AF743A645"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:rfc_430_eth-ib_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "643E47A5-E7AA-4321-99A1-05EEBD9A2B56"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:rfc_430_eth-ib:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1F32F262-519C-41BB-BF31-ECBCAC1ABEA9"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:rfc_450_eth-ib_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A91E019B-F0C5-4DF0-AE4C-E60F3D598F0C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:rfc_450_eth-ib:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C3C2EDF4-2982-4858-A960-7E7564E5B20A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:rfc_460r_pn_3tx_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "302995A9-E9CC-4477-B374-CE10F16A5E10"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:rfc_460r_pn_3tx:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F7544E2C-2E63-4C36-AB64-764B4393E377"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:rfc_470s_pn_3tx_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CCAB2CA6-EEC4-4E0D-B962-FC2C4EF06013"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:rfc_470s_pn_3tx:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD94CBFF-CC25-4122-96FE-2308A4D1659D"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:phoenixcontact:rfc_480s_pn_4tx_firmware:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3B383246-EF0A-466F-89EA-F61AFC447509"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:phoenixcontact:rfc_480s_pn_4tx:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6B043176-58CC-438C-92D9-99F479BB1C58"
}
]
}
]
}
] ,
2023-12-14 15:00:31 +00:00
"references" : [
{
"url" : "https://cert.vde.com/en/advisories/VDE-2023-055/" ,
2023-12-21 19:00:28 +00:00
"source" : "info@cert.vde.com" ,
"tags" : [
"Third Party Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://cert.vde.com/en/advisories/VDE-2023-055/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
2023-12-14 15:00:31 +00:00
}
]
}