{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-0757","assignerOrgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","state":"PUBLISHED","assignerShortName":"CERTVDE","dateReserved":"2023-02-09T07:59:40.921Z","datePublished":"2023-12-14T14:04:10.708Z","dateUpdated":"2024-08-02T05:24:33.525Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"MULTIPROG","vendor":"PHOENIX CONTACT","versions":[{"status":"affected","version":"all"}]},{"defaultStatus":"unaffected","product":"ProConOS eCLR (SDK)","vendor":"PHOENIX CONTACT","versions":[{"status":"affected","version":"all"}]}],"credits":[{"lang":"en","type":"reporter","user":"00000000-0000-4000-9000-000000000000","value":"Reid Wightman from Dragos, Inc."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device."}],"value":"Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-732","description":"CWE-732 Incorrect Permission Assignment for Critical Resource","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","shortName":"CERTVDE","dateUpdated":"2023-12-14T14:04:10.708Z"},"references":[{"url":"https://cert.vde.com/en/advisories/VDE-2023-051/"}],"source":{"advisory":"VDE-2023-051","defect":["CERT@VDE#64360"],"discovery":"EXTERNAL"},"title":"Phoenix Contact ProConOS prone to Incorrect Permission Assignment for Critical Resource","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T05:24:33.525Z"},"title":"CVE Program Container","references":[{"url":"https://cert.vde.com/en/advisories/VDE-2023-051/","tags":["x_transferred"]}]}]}}