// For flags

CVE-2023-3569

PHOENIX CONTACT: Denial-of-Service due to malicious XML files in TC ROUTER, TC CLOUD CLIENT and CLOUD CLIENT

Severity Score

4.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

Phoenix Contact TC Router 3002T-4G* versions prior to 2.0.2, TC Cloud Client 1002-4G* versions prior to 2.07.2, and Cloud Client 1101T-TX/TX versions prior to 2.06.10 suffer from cross site scripting and memory consumption vulnerabilities.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Multiple
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-07-10 CVE Reserved
  • 2023-08-08 CVE Published
  • 2023-08-14 First Exploit
  • 2025-02-27 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Phoenixcontact
Search vendor "Phoenixcontact"
Cloud Client 1101t-tx Firmware
Search vendor "Phoenixcontact" for product "Cloud Client 1101t-tx Firmware"
< 2.06.10
Search vendor "Phoenixcontact" for product "Cloud Client 1101t-tx Firmware" and version " < 2.06.10"
-
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Cloud Client 1101t-tx
Search vendor "Phoenixcontact" for product "Cloud Client 1101t-tx"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Tc Cloud Client 1002-4g Att Firmware
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g Att Firmware"
< 2.07.2
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g Att Firmware" and version " < 2.07.2"
-
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Tc Cloud Client 1002-4g Att
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g Att"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Tc Cloud Client 1002-4g Firmware
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g Firmware"
< 2.07.2
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g Firmware" and version " < 2.07.2"
-
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Tc Cloud Client 1002-4g
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Tc Cloud Client 1002-4g Vzw Firmware
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g Vzw Firmware"
< 2.07.2
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g Vzw Firmware" and version " < 2.07.2"
-
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Tc Cloud Client 1002-4g Vzw
Search vendor "Phoenixcontact" for product "Tc Cloud Client 1002-4g Vzw"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Tc Router 3002t-4g Att Firmware
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g Att Firmware"
< 2.07.2
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g Att Firmware" and version " < 2.07.2"
-
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Tc Router 3002t-4g Att
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g Att"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Tc Router 3002t-4g Firmware
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g Firmware"
< 2.07.2
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g Firmware" and version " < 2.07.2"
-
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Tc Router 3002t-4g
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g"
--
Safe
Phoenixcontact
Search vendor "Phoenixcontact"
Tc Router 3002t-4g Vzw Firmware
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g Vzw Firmware"
< 2.07.2
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g Vzw Firmware" and version " < 2.07.2"
-
Affected
in Phoenixcontact
Search vendor "Phoenixcontact"
Tc Router 3002t-4g Vzw
Search vendor "Phoenixcontact" for product "Tc Router 3002t-4g Vzw"
--
Safe