MEDIUM · 4.9

CVE-2023-3569

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload ...

Vulnerability Description

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

CVSS Score

4.9

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
PhoenixcontactCloud Client 1101T-Tx Firmware< 2.06.10
PhoenixcontactCloud Client 1101T-Tx-
PhoenixcontactTc Cloud Client 1002-4G Att Firmware< 2.07.2
PhoenixcontactTc Cloud Client 1002-4G Att-
PhoenixcontactTc Cloud Client 1002-4G Firmware< 2.07.2
PhoenixcontactTc Cloud Client 1002-4G-
PhoenixcontactTc Cloud Client 1002-4G Vzw Firmware< 2.07.2
PhoenixcontactTc Cloud Client 1002-4G Vzw-
PhoenixcontactTc Router 3002T-4G Att Firmware< 2.07.2
PhoenixcontactTc Router 3002T-4G Att-
PhoenixcontactTc Router 3002T-4G Firmware< 2.07.2
PhoenixcontactTc Router 3002T-4G-
PhoenixcontactTc Router 3002T-4G Vzw Firmware< 2.07.2
PhoenixcontactTc Router 3002T-4G Vzw-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-3569?

CVE-2023-3569 is a vulnerability with a CVSS score of 4.9 (MEDIUM). In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload ...

How severe is CVE-2023-3569?

CVE-2023-3569 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-3569?

Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Cloud Client 1101T-Tx Firmware, Phoenixcontact Cloud Client 1101T-Tx, Phoenixcontact Tc Cloud Client 1002-4G Att Firmware, Phoenixcontact Tc Cloud Client 1002-4G Att, Phoenixcontact Tc Cloud Client 1002-4G Firmware.