PT-2023-7105 · Phoenix Contact · Phoenix Contacts Energy Axc Pu

Published

2023-04-17

·

Updated

2023-04-27

·

CVE-2023-1109

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Phoenix Contacts ENERGY AXC PU versions (affected versions not specified)
Description The issue is related to a web service vulnerability that allows an authenticated restricted user of the web frontend to access, read, write, and create files throughout the file system using specially crafted URLs via the upload and download functionality. This may lead to full control of the service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-08132
CVE-2023-1109
GHSA-W923-8W64-F5GH

Affected Products

Phoenix Contacts Energy Axc Pu