CVE-2023-3569

Severity
4.9MEDIUM
EPSS
0.2%
top 55.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8

Description

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages14 packages

🔴Vulnerability Details

2
GHSA
GHSA-4322-9574-7cv6: In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 22023-08-08
CVEList
PHOENIX CONTACT: Denial-of-Service due to malicious XML files in TC ROUTER, TC CLOUD CLIENT and CLOUD CLIENT2023-08-08
CVE-2023-3569 (MEDIUM CVSS 4.9) | In PHOENIX CONTACTs TC ROUTER and T | cvebase.io