Vulnerability Description
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phoenixcontact | Cloud Client 1101T-Tx Firmware | < 2.06.10 |
| Phoenixcontact | Cloud Client 1101T-Tx | - |
| Phoenixcontact | Tc Cloud Client 1002-4G Att Firmware | < 2.07.2 |
| Phoenixcontact | Tc Cloud Client 1002-4G Att | - |
| Phoenixcontact | Tc Cloud Client 1002-4G Firmware | < 2.07.2 |
| Phoenixcontact | Tc Cloud Client 1002-4G | - |
| Phoenixcontact | Tc Cloud Client 1002-4G Vzw Firmware | < 2.07.2 |
| Phoenixcontact | Tc Cloud Client 1002-4G Vzw | - |
| Phoenixcontact | Tc Router 3002T-4G Att Firmware | < 2.07.2 |
| Phoenixcontact | Tc Router 3002T-4G Att | - |
| Phoenixcontact | Tc Router 3002T-4G Firmware | < 2.07.2 |
| Phoenixcontact | Tc Router 3002T-4G | - |
| Phoenixcontact | Tc Router 3002T-4G Vzw Firmware | < 2.07.2 |
| Phoenixcontact | Tc Router 3002T-4G Vzw | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/174152/Phoenix-Contact-TC-Cloud-TC-Router-2
- http://seclists.org/fulldisclosure/2023/Aug/12
- https://cert.vde.com/en/advisories/VDE-2023-017Third Party Advisory
- http://packetstormsecurity.com/files/174152/Phoenix-Contact-TC-Cloud-TC-Router-2
- http://seclists.org/fulldisclosure/2023/Aug/12
- https://cert.vde.com/en/advisories/VDE-2023-017Third Party Advisory
FAQ
What is CVE-2023-3569?
CVE-2023-3569 is a vulnerability with a CVSS score of 4.9 (MEDIUM). In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload ...
How severe is CVE-2023-3569?
CVE-2023-3569 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3569?
Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Cloud Client 1101T-Tx Firmware, Phoenixcontact Cloud Client 1101T-Tx, Phoenixcontact Tc Cloud Client 1002-4G Att Firmware, Phoenixcontact Tc Cloud Client 1002-4G Att, Phoenixcontact Tc Cloud Client 1002-4G Firmware.