QID 591178
Date Published: 2023-01-04
QID 591178: Phoenix Contact FL Network Manager Path Traversal Vulnerability (CVE-2021-32840,CVE-2021-32842)
AFFECTED PRODUCTS
The following Phoenix Contact products are affected:
FL Network Manager from version 4.0 up to 6.0
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Wow6432Node\Classes\FLNM64.netmax\shell\open\command"
Successful exploitation of this vulnerability with a specially crafted zip file an attacker could take over a vulnerable PC, gain unauthorized access to sensitive data, or affect the availability of the system.
Solution
Customers are advised to refer to CERT MITIGATIONS section CVE-2021-32840,CVE-2021-32842 for affected packages and patching details.
Vendor References
CVEs related to QID 591178
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-32840,CVE-2021-32842 |
|