PT-2018-1516 · Phoenix Contact · Fl Switch

Semen Sokolov

·

Publicado

2018-02-22

·

Atualizado

2018-06-20

·

CVE-2018-10729

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Phoenix Contact FL SWITCH versions 1.0 through 1.33
Description The issue is related to insufficient security mechanisms in the CGI applications of the firmware, allowing a remote attacker to access the contents of configuration files. An unauthenticated user can read the configuration file.
Recommendations For versions 1.0 through 1.33, restrict access to the configuration file to prevent unauthorized reading until a patch is available. Consider implementing additional security measures to protect the configuration files from unauthorized access.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01071
CVE-2018-10729

Produtos afetados

Fl Switch