CVE-2021-21004

Severity
6.1MEDIUM
EPSS
0.2%
top 52.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25
Latest updateMay 24

Description

In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:NExploitability: 2.1 | Impact: 4.7

🔴Vulnerability Details

2
GHSA
GHSA-p92q-6vw3-958m: In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based manage2022-05-24
CVEList
Cross-site Scripting Vulnerability in Phoenix Contact FL SWITCH SMCS series products2021-06-25
CVE-2021-21004 (MEDIUM CVSS 6.1) | In Phoenix Contact FL SWITCH SMCS s | cvebase.io