QID 591306

Date Published: 2023-02-03

QID 591306: Phoenix Contact FL SWITCH SMCS series switches Denial of Service (DoS) Multiple Vulnerabilities (VDE-2021-023)

AFFECTED PRODUCTS
FL SWITCH SMCS 16TX : Versions 4.70 and prior.
FL SWITCH SMCS 14TX/2FX : Versions 4.70 and prior.
FL SWITCH SMCS 14TX/2FX-SM : Versions 4.70 and prior.
FL SWITCH SMCS 8GT : Versions 4.70 and prior.
FL SWITCH SMCS 6GT/2SFP : Versions 4.70 and prior.
FL SWITCH SMCS 8TX-PN : Versions 4.70 and prior.
FL SWITCH SMCS 4TX-PN : Versions 4.70 and prior.
FL SWITCH SMCS 8TX : Versions 4.70 and prior.
FL SWITCH SMCS 6TX/2SFP : Versions 4.70 and prior.
FL SWITCH SMN 6TX/2POF-PN : Versions 4.70 and prior.
FL SWITCH SMN 8TX-PN : Versions 4.70 and prior.
FL SWITCH SMN 6TX/2FX : Versions 4.70 and prior.
FL SWITCH SMN 6TX/2FX SM : Versions 4.70 and prior.
FL NAT SMN 8TX : Versions 4.63 and prior.
FL NAT SMN 8TX-M : Versions 4.63 and prior.

QID Detection Logic:
This QID checks for the Vulnerable version of Phoenix Contact FL SWITCH SMCS series switches using passive scanning

Successful exploitation of these vulnerabilities may allow an attacker to provoke a denial of service to defeat certain management functions of the device or use the XSS vulnerability to attack the client PC.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to Phoenix contact MITIGATIONS section VDE-2021-023 for affected packages and patching details.

    CVEs related to QID 591306

    Software Advisories
    Advisory ID Software Component Link