CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
27.1%
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
Vendor | Product | Version | CPE |
---|---|---|---|
phoenixcontact | energy_axc_pu | * | cpe:2.3:a:phoenixcontact:energy_axc_pu:*:*:*:*:*:*:*:* |
phoenixcontact | infobox | - | cpe:2.3:h:phoenixcontact:infobox:-:*:*:*:*:*:*:* |
phoenixcontact | infobox_firmware | * | cpe:2.3:o:phoenixcontact:infobox_firmware:*:*:*:*:*:*:*:* |
phoenixcontact | smartrtu_axc_sg | - | cpe:2.3:h:phoenixcontact:smartrtu_axc_sg:-:*:*:*:*:*:*:* |
phoenixcontact | smartrtu_axc_sg_firmware | * | cpe:2.3:o:phoenixcontact:smartrtu_axc_sg_firmware:*:*:*:*:*:*:*:* |
phoenixcontact | smartrtu_axc_ig | - | cpe:2.3:h:phoenixcontact:smartrtu_axc_ig:-:*:*:*:*:*:*:* |
phoenixcontact | smartrtu_axc_ig_firmware | * | cpe:2.3:o:phoenixcontact:smartrtu_axc_ig_firmware:*:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
27.1%