CVE-2023-5592
Last modified
CVE-2023-5592 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phoenixcontact | Multiprog | All versions |
| Phoenixcontact | Proconos Eclr | All versions |
References
- https://cert.vde.com/en/advisories/VDE-2023-054/Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2023-054/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5592?
How severe is CVE-2023-5592?
How do I fix CVE-2023-5592?
Are you affected by CVE-2023-5592?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
