Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w923-8w64-f5gh

Опубликовано: 17 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

EPSS

Процентиль: 38%
0.00171
Низкий

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

CVSS3: 8.8
fstec
почти 3 года назад

Уязвимость веб-службы Phoenix Contacts ENERGY AXC PU терминалов управления и мониторинга промышленных процессов и систем автоматизации SMARTRTU AXC IG и SMARTRTU AXC SG, позволяющая нарушителю получить полный контроль над устройством

EPSS

Процентиль: 38%
0.00171
Низкий

8.8 High

CVSS3

Дефекты

CWE-22