← Back

CVE-2023-1109

nvd nist
Published: Apr 17, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: info@cert.vde.com (Secondary)

Description

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

Affected (4)

4 products
Energy Axc Pu
Infobox Firmware
Smartrtu Axc Sg Firmware
Smartrtu Axc Ig Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 01.00.00.00 to 04.15.00.00
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 01.00.00.00 to 02.02.00.00
Running on/withPlatform Versions
Phoenixcontact
Infobox
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 01.00.00.00 to 01.08.00.02
Running on/withPlatform Versions
Phoenixcontact
Smartrtu Axc Sg
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 01.00.00.00 to 01.02.00.01
Running on/withPlatform Versions
Phoenixcontact
Smartrtu Axc Ig
All versions

References (3)

Source: info@cert.vde.com
Not Applicable
Source: nvd@nist.gov
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.