PT-2018-1007 · Phoenix Contact · Fl Switch 3Xxx+2
Evgeniy Druzhinin
+1
·
Publicado
2018-01-11
·
Atualizado
2019-10-03
·
CVE-2017-16743
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products versions 1.0 through 1.32
Description
An issue with improper authorization was found, allowing a remote unauthenticated attacker to craft special HTTP requests to bypass web-service authentication and obtain administrative privileges on the device. This can be achieved by exploiting weaknesses in the authorization procedure, enabling the attacker to gain administrative access through specially formed HTTP requests.
Recommendations
For versions 1.0 through 1.32, consider restricting access to the web-service until a patch is available, and avoid using the device's administrative features over untrusted networks. As a temporary workaround, limit the device's exposure to the internet and isolate it from untrusted networks to minimize the risk of exploitation.
Correção
Incorrect Authorization
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Fl Switch 3Xxx
Fl Switch 48Xx
Fl Switch 4Xxx