CVE-2017-16741
published 2018-01-12CVE-2017-16741: An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote…
PriorityP428medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.21%
65.0th percentile
An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on the device to read diagnostic information.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenixcontact | fl_switch_3004t-fx_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3004t-fx_st_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3005_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3005t_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3006t-2fx_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3006t-2fx_sm_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3006t-2fx_st_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3008_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3008t_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3012e-2fx_sm_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3012e-2sfx_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3016_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3016e_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_3016t_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4000t-8poe-2sfp-r_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4008t-2gt-3fx_sm_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4008t-2gt-4fx_sm_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4008t-2sfp_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4012t-2gt-2fx_st_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4012t_2gt_2fx_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4800e-24fx-4gc_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4800e-24fx_sm-4gc_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4808e-16fx-4gc_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4808e-16fx_lc-4gc_firmware | 1.0 – 1.32 | — |
| phoenixcontact | fl_switch_4808e-16fx_sm-4gc_firmware | 1.0 – 1.32 | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
PHOENIX CONTACT FL SWITCH
cisa_ics·2018-01-11
PHOENIX CONTACT FL SWITCH
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
PHOENIX CONTACT FL SWITCH
Last RevisedJanuary 11, 2018
Alert CodeICSA-18-011-03
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: PHOENIX CONTACT
Equipment: FL SWITCH
Vulnerabilities: Improper Authorization, Information Exposure
## AFFECTED PRODUCTS
All FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32 are affected.
## IMPACT
Successful exploitation of these vulnerabilities may allow an unauthenticated remote attacker to gain administrative privileges and expose information to unauthenticated users.
## M
GHSA
GHSA-6c6j-r563-746g: An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1
ghsa_unreviewed·2022-05-14
CVE-2017-16741 [MEDIUM] CWE-200 GHSA-6c6j-r563-746g: An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1
An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on the device to read diagnostic information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-01-12
Published