QID 590572

Date Published: 2021-12-23

QID 590572: PHOENIX CONTACT FL SWITCH Multiple Vulnerabilities (ICSA-19-024-02)

AFFECTED PRODUCTS
Phoenix Contact reports the vulnerabilities affect the following products:
FL SWITCH 3xxx, 4xxx and 48xx versions prior to Version 1.35.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may allow attackers to have user privileges, gain access to the switch, read user credentials, deny access to the switch, or perform man-in-the-middle attacks.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-19-024-02 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-19-024-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-19-024-02