CVE-2023-1109
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: info@cert.vde.com (Secondary)
Description
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 01.00.00.00 to 04.15.00.00 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 01.00.00.00 to 02.02.00.00 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Infobox | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 01.00.00.00 to 01.08.00.02 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Smartrtu Axc Sg | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 01.00.00.00 to 01.02.00.01 |
| Running on/with | Platform Versions |
|---|---|
Phoenixcontact Smartrtu Axc Ig | All versions |
References (3)
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Timeline
No history available yet.