4.9
CVSSv3

CVE-2023-3569

Published: 08/08/2023 Updated: 14/08/2023
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions before 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX before 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

Vulnerable Product Search on Vulmon Subscribe to Product

phoenixcontact cloud_client_1101t-tx_firmware

phoenixcontact tc_cloud_client_1002-4g_att_firmware

phoenixcontact tc_cloud_client_1002-4g_firmware

phoenixcontact tc_cloud_client_1002-4g_vzw_firmware

phoenixcontact tc_router_3002t-4g_att_firmware

phoenixcontact tc_router_3002t-4g_firmware

phoenixcontact tc_router_3002t-4g_vzw_firmware

Exploits

Phoenix Contact TC Router 3002T-4G* versions prior to 202, TC Cloud Client 1002-4G* versions prior to 2072, and Cloud Client 1101T-TX/TX versions prior to 20610 suffer from cross site scripting and memory consumption vulnerabilities ...