In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-23395 In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2025-02-05T21:19:53.289Z

Reserved: 2023-03-01T05:58:56.947Z

Link: CVE-2023-1109

cve-icon Vulnrichment

Updated: 2024-08-02T05:32:46.389Z

cve-icon NVD

Status : Modified

Published: 2023-04-17T08:15:07.627

Modified: 2024-11-21T07:38:28.530

Link: CVE-2023-1109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.