First published: Mon Dec 11 2017(Updated: )
A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The cross-site scripting vulnerability has been identified, which may allow remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
PhoenixContact FL COMserver BASIC 232 | =2.40 | |
Phoenixcontact FL Comserver Basic 232 Firmware | ||
Phoenix Contact FL COMSERVER Uni 422 | =2.40 | |
Phoenix Contact FL COMSERVER Uni 422 | ||
Phoenixcontact Fl Comserver Bas 485-t Firmware | =2.40 | |
Phoenixcontact Fl Comserver Bas 485-t Firmware | ||
Phoenix Contact FL Comserver | =1.99 | |
Phoenix Contact FL COM SERVER RS232 | ||
Phoenix Contact FL COM Server | =1.99 | |
Phoenixcontact Fl Com Server Rs485 Firmware | ||
Phoenixcontact Psi-modem/eth Firmware | =2.20 | |
Phoenix Contact Psi-modem/eth | ||
Phoenixcontact FL ComServer BAS 422 | =2.40 | |
Phoenix Contact FL ComServer Basic 422 | ||
Phoenixcontact Fl Comserver Basic 485 Firmware | =2.40 | |
Phoenixcontact FL Comserver | ||
Phoenix Contact FL Comserver Uni 485 Firmware | =2.40 | |
Phoenixcontact Fl Comserver Uni 485-t Firmware | ||
Phoenix Contact FL Comserver Uni 485 Firmware | =2.40 | |
Phoenixcontact Fl Comserver Uni 485 Firmware | ||
Phoenixcontact Fl Comserver Uni 232 Firmware | =2.40 | |
Phoenixcontact Fl Comserver Uni 232 Firmware | ||
Phoenixcontact Fl Comserver Basic 422 Firmware | =2.40 | |
Phoenixcontact FL Comserver Basic 422 Firmware | ||
Phoenixcontact FL Comserver Basic 232 Firmware | =2.40 | |
PhoenixContact FL COMserver BASIC 232 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16723 is classified as a medium severity vulnerability due to its potential impact on the confidentiality and integrity of affected devices.
To remediate CVE-2017-16723, update the devices to firmware versions 1.99 or 2.20 and above.
CVE-2017-16723 affects various Phoenix Contact FL Comserver models running firmware versions prior to 1.99, 2.20, or 2.40.
Yes, CVE-2017-16723 is categorized as a Cross-site Scripting (XSS) vulnerability.
If CVE-2017-16723 is not addressed, attackers may exploit the vulnerability to inject malicious scripts, which can lead to unauthorized access and data manipulation.