CVE-2023-1109
📛 CVE Title
PHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web service
Description
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- CERTVDE
- CVSS severity
- HIGH
- CVSS score
- 8.8 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Effective score
- 8.8 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-22 - Reserved
- 2023-03-01
- Published
- 2023-04-17 09:32 UTC
- Last updated
- 2025-02-05 22:19 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/1xxx/CVE-2023-1109.json
- Linked Threat
- CVE-2023-1109 — PHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web service
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- EPSS score
- 0.0076 (probability of exploitation in next 30 days)
- EPSS percentile
- 50.71% vs all CVEs — higher = more likely to be exploited, as of 2026-07-01
NVD / KEV / EPSS data refreshed 2026-07-02 12:44 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-23395 - Assigner
- CERTVDE
- Published
- Apr 17, 2023, 7:32:24 AM
- Updated
- Feb 5, 2025, 9:19:53 PM
- EUVD base score (CVSS 3.1)
-
8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.6400
- Vendors
- PHOENIX CONTACT
- Products
-
SMARTRTU AXC IG (1264328) (V01.00.00.00 ≤V01.02.00.01)SMARTRTU AXC SG (1110435) (V01.00.00.00 ≤V01.08.00.02)Infobox (1169323 ) (V01.00.00.00 ≤V02.02.00.00)ENERGY AXC PU (1264327) (V01.00.00.00 ≤V04.15.00.00)
- Aliases
-
GHSA-w923-8w64-f5gh
ENISA description: In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
EUVD references (1)
Affected products (4)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| PHOENIX CONTACT | ENERGY AXC PU (1264327) |
V01.00.00.00 (affected)
|
— |
| PHOENIX CONTACT | SMARTRTU AXC SG (1110435) |
V01.00.00.00 (affected)
|
— |
| PHOENIX CONTACT | SMARTRTU AXC IG (1264328) |
V01.00.00.00 (affected)
|
— |
| PHOENIX CONTACT | Infobox (1169323 ) |
V01.00.00.00 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (16)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:0patch.com
Fixing what's really important. The goal of 0patch is not to micropatch every vulnerability but the important ones, such as those exploited in the wild or those without official vendor patches. These are some of our most popular micropatches.
2026-06-02 14:27 UTC -
web:access.redhat.com
Learn about our open source products, services, and company. You are here
2026-06-02 14:27 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-06-02 14:27 UTC -
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.
2026-06-02 14:27 UTC -
web:www.microsoft.com
Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.
2026-06-02 14:27 UTC -
web:www.tenable.com
Microsoft patched 57 CVEs in its November 2023 Patch Tuesday release, with three rated critical and 54 rated important. We omitted one vulnerability from our counts this month, CVE - 2023 -24023, a Bluetooth Vulnerability as this flaw was reported through MITRE.
2026-06-02 14:27 UTC -
web:nvd.nist.gov
This is a potential security issue, you are being redirected to https://nvd.nist.gov
2026-05-22 05:37 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:37 UTC -
web:support.esri.com
Learn about updates and download patches for your ArcGIS software. To download the Esri products, please visit My Esri or the Product Support download page.
2026-05-22 05:37 UTC -
web:support.servicenow.com
This document lists all the released Store applications and schema changes for Vulnerability Response and Configuration Compliance. Vulnerability Response and Configuration Compliance Compatibility Matrix
2026-05-22 05:37 UTC -
web:www.fbi.gov
For patch information on CVEs identified in this advisory, refer to the Appendix: Patch Information and Additional Resources for Top Exploited Vulnerabilities.
2026-05-22 05:37 UTC -
web:www.crowdstrike.com
Microsoft has released security updates for 58 vulnerabilities, including five zero-days, three of which are being actively exploited. One of the zero-days ( CVE - 2023 -36025) is a Windows SmartScreen Security Feature Bypass Vulnerability, the second ( CVE - 2023 -36033) is a privilege escalation vulnerability in the Windows DWM Core Library, and the third ( CVE - 2023 -36036) is another privilege ...
2026-05-22 05:37 UTC -
web:app.opencve.io
Explore the latest vulnerabilities and security issues in the CVE database
2026-05-22 05:37 UTC -
web:attack.mitre.org
This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...
2026-05-22 05:37 UTC -
web:blog.qualys.com
Qualys highlights November 2023 Patch Tuesday updates from Microsoft and Adobe, covering vulnerabilities needing prompt remediation .
2026-05-22 05:37 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-22 05:37 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-1109.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:32:46.389Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://cert.vde.com/en/advisories/VDE-2023-003/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1109",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-02-05T21:19:48.861651Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-02-05T21:19:53.289Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ENERGY AXC PU (1264327)",
"vendor": "PHOENIX CONTACT",
"versions": [
{
"lessThanOrEqual": "V04.15.00.00",
"status": "affected",
"version": "V01.00.00.00",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "SMARTRTU AXC SG (1110435)",
"vendor": "PHOENIX CONTACT",
"versions": [
{
"lessThanOrEqual": "V01.08.00.02",
"status": "affected",
"version": "V01.00.00.00",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "SMARTRTU AXC IG (1264328)",
"vendor": "PHOENIX CONTACT",
"versions": [
{
"lessThanOrEqual": "V01.02.00.01",
"status": "affected",
"version": "V01.00.00.00",
"versionType": "custom"
}
]
},
{
"defaultStatus": "affected",
"product": "Infobox (1169323 )",
"vendor": "PHOENIX CONTACT",
"versions": [
{
"lessThanOrEqual": "V02.02.00.00",
"status": "affected",
"version": "V01.00.00.00",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Laokoon SecurITy GmbH on behalf of E.ON Digital Technology GmbH"
}
],
"datePublic": "2023-04-11T08:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service."
}
],
"value": "In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-04-17T07:32:24.262Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://cert.vde.com/en/advisories/VDE-2023-003/"
}
],
"source": {
"advisory": "VDE-2023-003",
"defect": [
"CERT@VDE#64407"
],
"discovery": "EXTERNAL"
},
"title": "PHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web service",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2023-1109",
"datePublished": "2023-04-17T07:32:24.262Z",
"dateReserved": "2023-03-01T05:58:56.947Z",
"dateUpdated": "2025-02-05T21:19:53.289Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}