CVE-2023-1109

HIGH

Phoenix Contact ENERGY AXC PU < 04.15.00.00 - Authenticated Path Traversal via Web Service Upload/Download

Title source: llm
STIX 2.1

Description

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0076
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (4)
phoenixcontact/energy_axc_pu 01.00.00.00 - 04.15.00.00
phoenixcontact/infobox_firmware 01.00.00.00 - 02.02.00.00
phoenixcontact/smartrtu_axc_ig_firmware 01.00.00.00 - 01.02.00.01
phoenixcontact/smartrtu_axc_sg_firmware 01.00.00.00 - 01.08.00.02
Published Apr 17, 2023
Tracked Since Feb 18, 2026