CVE-2021-21005

CWE-362Race Condition3 documents3 sources
Severity
7.5HIGH
EPSS
0.0%
top 86.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25
Latest updateMay 24

Description

In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-jmcx-w32h-8qj4: In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the2022-05-24
CVEList
Race Condition Vulnerability in Phoenix Contact FL SWITCH SMCS series products2021-06-25
CVE-2021-21005 (HIGH CVSS 7.5) | In Phoenix Contact FL SWITCH SMCS s | cvebase.io