PT-2023-7105 · Phoenix Contact · Phoenix Contacts Energy Axc Pu

CVE-2023-1109

·

Publicado

2023-04-17

·

Atualizado

2023-04-27

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Phoenix Contacts ENERGY AXC PU versions (affected versions not specified)
Description The issue is related to a web service vulnerability that allows an authenticated restricted user of the web frontend to access, read, write, and create files throughout the file system using specially crafted URLs via the upload and download functionality. This may lead to full control of the service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08132
CVE-2023-1109
GHSA-W923-8W64-F5GH

Produtos afetados

Phoenix Contacts Energy Axc Pu