Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
The vulnerability results from improper assignment of permissions to critical resources (CWE-732). Due to misconfigured or insufficiently restrictive permissions on key system resources, an attacker can access them without requiring authentication. The attack is possible remotely over the network, without user interaction, and without any prerequisites on the attacker's side.
An attacker can gain full control over the vulnerable device, which includes reading and modifying configuration, manipulating control processes, and potentially disrupting or stopping the operation of industrial installation.
Apply patches available from the manufacturer according to references (https://cert.vde.com/en/advisories/VDE-2023-055/). Until updates are implemented, it is recommended to isolate vulnerable devices from the network, restrict access to them only from trusted hosts using a firewall, and avoid directly exposing devices to public networks.
Phoenix Contact Automation Worx Software Suite, Phoenix Contact AXC 1050 (Firmware), Phoenix Contact AXC 1050 XC (Firmware) — exact versions indicated in manufacturer references (CERT@VDE VDE-2023-055)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPhoenixcontact Automationworx Software Suite
APPPhoenixcontactall versionsPhoenixcontact Axc 1050
HWPhoenixcontactall versionsPhoenixcontact Axc 1050 Firmware
OSPhoenixcontactall versionsPhoenixcontact Axc 1050 Xc
HWPhoenixcontactall versionsPhoenixcontact Axc 1050 Xc Firmware
OSPhoenixcontactall versionsPhoenixcontact Axc 3050
HWPhoenixcontactall versionsPhoenixcontact Axc 3050 Firmware
OSPhoenixcontactall versionsPhoenixcontact Config\+
APPPhoenixcontactall versionsPhoenixcontact Fc 350 Pci Eth
HWPhoenixcontactall versionsPhoenixcontact Fc 350 Pci Eth Firmware
OSPhoenixcontactall versionsPhoenixcontact Ilc1x0
HWPhoenixcontactall versionsPhoenixcontact Ilc1x0 Firmware
OSPhoenixcontactall versionsPhoenixcontact Ilc1x1
HWPhoenixcontactall versionsPhoenixcontact Ilc1x1 Firmware
OSPhoenixcontactall versionsPhoenixcontact Ilc 3xx
HWPhoenixcontactall versionsPhoenixcontact Ilc 3xx Firmware
OSPhoenixcontactall versionsPhoenixcontact Pc Worx
APPPhoenixcontactall versionsPhoenixcontact Pc Worx Express
APPPhoenixcontactall versionsPhoenixcontact Pc Worx Rt Basic
HWPhoenixcontactall versionsPhoenixcontact Pc Worx Rt Basic Firmware
OSPhoenixcontactall versionsPhoenixcontact Pc Worx Srt
APPPhoenixcontactall versionsPhoenixcontact Rfc 430 Eth Ib
HWPhoenixcontactall versionsPhoenixcontact Rfc 430 Eth Ib Firmware
OSPhoenixcontactall versionsPhoenixcontact Rfc 450 Eth Ib
HWPhoenixcontactall versionsPhoenixcontact Rfc 450 Eth Ib Firmware
OSPhoenixcontactall versionsPhoenixcontact Rfc 460r Pn 3tx
HWPhoenixcontactall versionsPhoenixcontact Rfc 460r Pn 3tx Firmware
OSPhoenixcontactall versionsPhoenixcontact Rfc 470s Pn 3tx
HWPhoenixcontactall versionsPhoenixcontact Rfc 470s Pn 3tx Firmware
OSPhoenixcontactall versionsPhoenixcontact Rfc 480s Pn 4tx
HWPhoenixcontactall versions
Related vulnerabilities
Phoenix Contact AXC: nieautoryzowane wgranie złośliwego kodu do sterownika PLC
Phoenix Contact ILC — brak uwierzytelnienia na porcie 1962 (dostęp zdalny)
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthen...
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended sco...
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could...