CVE-2023-3526
published 2023-08-08CVE-2023-3526: In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote…
PriorityP354critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
1.58%
72.8th percentile
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | cloud_client_1101t-tx_tx | < 2.06.10 | 2.06.10 |
| phoenix_contact | tc_cloud_client_1002-4g | < 2.07.2 | 2.07.2 |
| phoenix_contact | tc_cloud_client_1002-4g_att | < 2.07.2 | 2.07.2 |
| phoenix_contact | tc_cloud_client_1002-4g_vzw | < 2.07.2 | 2.07.2 |
| phoenix_contact | tc_router_3002t-4g | < 2.07.2 | 2.07.2 |
| phoenix_contact | tc_router_3002t-4g_att | < 2.07.2 | 2.07.2 |
| phoenix_contact | tc_router_3002t-4g_vzw | < 2.07.2 | 2.07.2 |
| phoenixcontact | cloud_client_1101t-tx_firmware | < 2.06.10 | 2.06.10 |
| phoenixcontact | tc_cloud_client_1002-4g_att_firmware | < 2.07.2 | 2.07.2 |
| phoenixcontact | tc_cloud_client_1002-4g_firmware | < 2.07.2 | 2.07.2 |
| phoenixcontact | tc_cloud_client_1002-4g_vzw_firmware | < 2.07.2 | 2.07.2 |
| phoenixcontact | tc_router_3002t-4g_att_firmware | < 2.07.2 | 2.07.2 |
| phoenixcontact | tc_router_3002t-4g_firmware | < 2.07.2 | 2.07.2 |
| phoenixcontact | tc_router_3002t-4g_vzw_firmware | < 2.07.2 | 2.07.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Phoenix Contact TC ROUTER and TC CLOUD CLIENT
cisa_ics·2023-09-07·CVSS 9.6
[CRITICAL] Phoenix Contact TC ROUTER and TC CLOUD CLIENT
ICS Advisory
##
Phoenix Contact TC ROUTER and TC CLOUD CLIENT
Release DateSeptember 07, 2023
Alert CodeICSA-23-250-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.6
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Phoenix Contact
- Equipment: TC ROUTER and TC CLOUD CLIENT
- Vulnerabilities: Cross-site Scripting, XML Entity Expansion
## 2. RISK EVALUATION
Successful exploitation of this these vulnerabilities could execute code in the context of the user's browser or cause a denial of service.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Phoenix contact reports that the following products are affected:
- TC ROUTER 3002T-4G: versions prior to 2.07.2
- TC ROUTER 3002T-4G ATT: versions prior to 2.07.2
- TC ROUTER 3
GHSA
GHSA-v33q-q39m-425m: In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2
ghsa_unreviewed·2023-08-08
CVE-2023-3526 [CRITICAL] CWE-79 GHSA-v33q-q39m-425m: In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/174152/Phoenix-Contact-TC-Cloud-TC-Router-2.x-XSS-Memory-Consumption.htmlhttp://seclists.org/fulldisclosure/2023/Aug/12https://cert.vde.com/en/advisories/VDE-2023-017http://packetstormsecurity.com/files/174152/Phoenix-Contact-TC-Cloud-TC-Router-2.x-XSS-Memory-Consumption.htmlhttp://seclists.org/fulldisclosure/2023/Aug/12https://cert.vde.com/en/advisories/VDE-2023-017
2023-08-08
Published