CVE Feed

    Dashboard / CVE / CVE-2023-3526

    CVE-2023-3526

    In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.

    Published:Aug 8, 2023
    Last Modified:Feb 27, 2025
    EPS:Aug 8, 2023
    EPSS Score:0.00613
    CVSS Score:9.6

    Affected Products

    Vendor
    Phoenixcontact
    Product
    Cloud Client 1101t-tx
    Vendor
    Phoenixcontact
    Product
    Cloud Client 1101t-tx Firmware
    Vendor
    Phoenixcontact
    Product
    Tc Cloud Client 1002-4g
    Vendor
    Phoenixcontact
    Product
    Tc Cloud Client 1002-4g Att
    Vendor
    Phoenixcontact
    Product
    Tc Cloud Client 1002-4g Att Firmware
    Vendor
    Phoenixcontact
    Product
    Tc Cloud Client 1002-4g Firmware
    Vendor
    Phoenixcontact
    Product
    Tc Cloud Client 1002-4g Vzw
    Vendor
    Phoenixcontact
    Product
    Tc Cloud Client 1002-4g Vzw Firmware
    Vendor
    Phoenixcontact
    Product
    Tc Router 3002t-4g
    Vendor
    Phoenixcontact
    Product
    Tc Router 3002t-4g Att
    Vendor
    Phoenixcontact
    Product
    Tc Router 3002t-4g Att Firmware
    Vendor
    Phoenixcontact
    Product
    Tc Router 3002t-4g Firmware
    Vendor
    Phoenixcontact
    Product
    Tc Router 3002t-4g Vzw
    Vendor
    Phoenixcontact
    Product
    Tc Router 3002t-4g Vzw Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High