PT-2018-1007 · Phoenix Contact · Fl Switch 3Xxx+2

Evgeniy Druzhinin

+1

·

Publicado

2018-01-11

·

Atualizado

2019-10-03

·

CVE-2017-16743

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products versions 1.0 through 1.32
Description An issue with improper authorization was found, allowing a remote unauthenticated attacker to craft special HTTP requests to bypass web-service authentication and obtain administrative privileges on the device. This can be achieved by exploiting weaknesses in the authorization procedure, enabling the attacker to gain administrative access through specially formed HTTP requests.
Recommendations For versions 1.0 through 1.32, consider restricting access to the web-service until a patch is available, and avoid using the device's administrative features over untrusted networks. As a temporary workaround, limit the device's exposure to the internet and isolate it from untrusted networks to minimize the risk of exploitation.

Correção

Incorrect Authorization

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00226
CVE-2017-16743

Produtos afetados

Fl Switch 3Xxx
Fl Switch 48Xx
Fl Switch 4Xxx