CVE-2023-46144

Published Dec 14, 2023

Last updated 2 months ago

Overview

Description
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
Source
info@cert.vde.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

info@cert.vde.com
CWE-494

Social media

Hype score
Not currently trending

Configurations