cbcvebase.
CVE-2023-3569
published 2023-08-08

CVE-2023-3569: In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote…

PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
1.02%
59.4th percentile
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

Affected

14 ranges
VendorProductVersion rangeFixed in
phoenix_contactcloud_client_1101t-tx_tx< 2.06.102.06.10
phoenix_contacttc_cloud_client_1002-4g< 2.07.22.07.2
phoenix_contacttc_cloud_client_1002-4g_att< 2.07.22.07.2
phoenix_contacttc_cloud_client_1002-4g_vzw< 2.07.22.07.2
phoenix_contacttc_router_3002t-4g< 2.07.22.07.2
phoenix_contacttc_router_3002t-4g_att< 2.07.22.07.2
phoenix_contacttc_router_3002t-4g_vzw< 2.07.22.07.2
phoenixcontactcloud_client_1101t-tx_firmware< 2.06.102.06.10
phoenixcontacttc_cloud_client_1002-4g_att_firmware< 2.07.22.07.2
phoenixcontacttc_cloud_client_1002-4g_firmware< 2.07.22.07.2
phoenixcontacttc_cloud_client_1002-4g_vzw_firmware< 2.07.22.07.2
phoenixcontacttc_router_3002t-4g_att_firmware< 2.07.22.07.2
phoenixcontacttc_router_3002t-4g_firmware< 2.07.22.07.2
phoenixcontacttc_router_3002t-4g_vzw_firmware< 2.07.22.07.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.