First published: Mon Apr 17 2023(Updated: )
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenixcontact Energy Axc Pu | >=01.00.00.00<=04.15.00.00 | |
Phoenixcontact Infobox Firmware | >=01.00.00.00<=02.02.00.00 | |
Phoenixcontact Infobox | ||
Phoenixcontact Smartrtu Axc Sg Firmware | >=01.00.00.00<=01.08.00.02 | |
Phoenixcontact Smartrtu Axc Sg | ||
Phoenixcontact Smartrtu Axc Ig Firmware | >=01.00.00.00<=01.02.00.01 | |
Phoenixcontact Smartrtu Axc Ig |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-1109 is high with a severity value of 8.8.
Phoenix Contacts ENERGY AXC PU, Phoenixcontact Infobox Firmware, Phoenixcontact Smartrtu Axc Sg Firmware, and Phoenixcontact Smartrtu Axc Ig Firmware are affected by CVE-2023-1109.
An authenticated restricted user can access, read, write, and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service.
CVE-2023-1109 can lead to full control of the service.
Apply the appropriate patches or updates provided by Phoenix Contacts to mitigate CVE-2023-1109.