s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-1109

📛 CVE Title

PHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web service

Description

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

Overview

State
PUBLISHED
Assigner (CNA)
CERTVDE
CVSS severity
HIGH
CVSS score
CVSS 8.8 / 10 8.8 8.8 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Effective score
8.8 / 10 HIGH source: CNA overview
CWE(s)
CWE-22
Reserved
2023-03-01
Published
2023-04-17 09:32 UTC
Last updated
2025-02-05 22:19 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/1xxx/CVE-2023-1109.json
Linked Threat
CVE-2023-1109 — PHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web service

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

EPSS score
0.0076 (probability of exploitation in next 30 days)
EPSS percentile
50.71% vs all CVEs — higher = more likely to be exploited, as of 2026-07-01

NVD / KEV / EPSS data refreshed 2026-07-02 12:44 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-23395
Assigner
CERTVDE
Published
Apr 17, 2023, 7:32:24 AM
Updated
Feb 5, 2025, 9:19:53 PM
EUVD base score (CVSS 3.1)
8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EUVD-reported EPSS
0.6400
Vendors
PHOENIX CONTACT
Products
SMARTRTU AXC IG (1264328) (V01.00.00.00 ≤V01.02.00.01)
SMARTRTU AXC SG (1110435) (V01.00.00.00 ≤V01.08.00.02)
Infobox (1169323 ) (V01.00.00.00 ≤V02.02.00.00)
ENERGY AXC PU (1264327) (V01.00.00.00 ≤V04.15.00.00)
Aliases
GHSA-w923-8w64-f5gh

ENISA description: In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

EUVD references (1)

Affected products (4)

VendorProductVersionsPlatforms
PHOENIX CONTACT ENERGY AXC PU (1264327) V01.00.00.00 (affected)
PHOENIX CONTACT SMARTRTU AXC SG (1110435) V01.00.00.00 (affected)
PHOENIX CONTACT SMARTRTU AXC IG (1264328) V01.00.00.00 (affected)
PHOENIX CONTACT Infobox (1169323 ) V01.00.00.00 (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

MITRE references (1) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (16)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:0patch.com

    Fixing what's really important. The goal of 0patch is not to micropatch every vulnerability but the important ones, such as those exploited in the wild or those without official vendor patches. These are some of our most popular micropatches.

    2026-06-02 14:27 UTC
  • web:access.redhat.com

    Learn about our open source products, services, and company. You are here

    2026-06-02 14:27 UTC
  • web:nvd.nist.gov

    The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...

    2026-06-02 14:27 UTC
  • web:www.cisa.gov

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.

    2026-06-02 14:27 UTC
  • web:www.microsoft.com

    Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.

    2026-06-02 14:27 UTC
  • web:www.tenable.com

    Microsoft patched 57 CVEs in its November 2023 Patch Tuesday release, with three rated critical and 54 rated important. We omitted one vulnerability from our counts this month, CVE - 2023 -24023, a Bluetooth Vulnerability as this flaw was reported through MITRE.

    2026-06-02 14:27 UTC
  • web:nvd.nist.gov

    This is a potential security issue, you are being redirected to https://nvd.nist.gov

    2026-05-22 05:37 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 05:37 UTC
  • web:support.esri.com

    Learn about updates and download patches for your ArcGIS software. To download the Esri products, please visit My Esri or the Product Support download page.

    2026-05-22 05:37 UTC
  • web:support.servicenow.com

    This document lists all the released Store applications and schema changes for Vulnerability Response and Configuration Compliance. Vulnerability Response and Configuration Compliance Compatibility Matrix

    2026-05-22 05:37 UTC
  • web:www.fbi.gov

    For patch information on CVEs identified in this advisory, refer to the Appendix: Patch Information and Additional Resources for Top Exploited Vulnerabilities.

    2026-05-22 05:37 UTC
  • web:www.crowdstrike.com

    Microsoft has released security updates for 58 vulnerabilities, including five zero-days, three of which are being actively exploited. One of the zero-days ( CVE - 2023 -36025) is a Windows SmartScreen Security Feature Bypass Vulnerability, the second ( CVE - 2023 -36033) is a privilege escalation vulnerability in the Windows DWM Core Library, and the third ( CVE - 2023 -36036) is another privilege ...

    2026-05-22 05:37 UTC
  • web:app.opencve.io

    Explore the latest vulnerabilities and security issues in the CVE database

    2026-05-22 05:37 UTC
  • web:attack.mitre.org

    This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...

    2026-05-22 05:37 UTC
  • web:blog.qualys.com

    Qualys highlights November 2023 Patch Tuesday updates from Microsoft and Adobe, covering vulnerabilities needing prompt remediation .

    2026-05-22 05:37 UTC
  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

    2026-05-22 05:37 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2023-1109.json.

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T05:32:46.389Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://cert.vde.com/en/advisories/VDE-2023-003/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-1109",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-02-05T21:19:48.861651Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-02-05T21:19:53.289Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "ENERGY AXC PU (1264327)",
          "vendor": "PHOENIX CONTACT",
          "versions": [
            {
              "lessThanOrEqual": "V04.15.00.00",
              "status": "affected",
              "version": "V01.00.00.00",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "SMARTRTU AXC SG (1110435)",
          "vendor": "PHOENIX CONTACT",
          "versions": [
            {
              "lessThanOrEqual": "V01.08.00.02",
              "status": "affected",
              "version": "V01.00.00.00",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "SMARTRTU AXC IG (1264328)",
          "vendor": "PHOENIX CONTACT",
          "versions": [
            {
              "lessThanOrEqual": "V01.02.00.01",
              "status": "affected",
              "version": "V01.00.00.00",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Infobox (1169323 )",
          "vendor": "PHOENIX CONTACT",
          "versions": [
            {
              "lessThanOrEqual": "V02.02.00.00",
              "status": "affected",
              "version": "V01.00.00.00",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Laokoon SecurITy GmbH on behalf of E.ON Digital Technology GmbH"
        }
      ],
      "datePublic": "2023-04-11T08:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service."
            }
          ],
          "value": "In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-126",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-126 Path Traversal"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-22",
              "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-04-17T07:32:24.262Z",
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE"
      },
      "references": [
        {
          "url": "https://cert.vde.com/en/advisories/VDE-2023-003/"
        }
      ],
      "source": {
        "advisory": "VDE-2023-003",
        "defect": [
          "CERT@VDE#64407"
        ],
        "discovery": "EXTERNAL"
      },
      "title": "PHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web service",
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "cveId": "CVE-2023-1109",
    "datePublished": "2023-04-17T07:32:24.262Z",
    "dateReserved": "2023-03-01T05:58:56.947Z",
    "dateUpdated": "2025-02-05T21:19:53.289Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}