Lucene search

K
cveCERTVDECVE-2023-5592
HistoryDec 14, 2023 - 2:15 p.m.

CVE-2023-5592

2023-12-1414:15:45
CWE-494
CERTVDE
web.nvd.nist.gov
14
security
vulnerability
integrity check
phoenix contact
multiprog
proconos
eclr
remote attack

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

36.3%

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.

Affected configurations

Nvd
Node
phoenixcontactmultiprog
Node
phoenixcontactproconos_eclr
VendorProductVersionCPE
phoenixcontactmultiprog*cpe:2.3:a:phoenixcontact:multiprog:*:*:*:*:*:*:*:*
phoenixcontactproconos_eclr*cpe:2.3:a:phoenixcontact:proconos_eclr:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "MULTIPROG",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "status": "affected",
        "version": "all"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "ProConOS eCLR (SDK)",
    "vendor": "PHOENIX CONTACT",
    "versions": [
      {
        "status": "affected",
        "version": "all"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

36.3%

Related for CVE-2023-5592