First published: Fri Jan 12 2018(Updated: )
An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on the device to read diagnostic information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenix Contact FL Switch 3005 Firmware | >=1.0<=1.32 | |
Phoenix Contact FL Switch 3005 | ||
Phoenixcontact Fl Switch 3005t Firmware | >=1.0<=1.32 | |
Phoenix Contact FL Switch 3005T | ||
Phoenixcontact Fl Switch 3004t-fx St Firmware | >=1.0<=1.32 | |
Phoenix Contact FL Switch 3004T-FX | ||
Phoenixcontact FL Switch 3004T-FX ST Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 3004t-fx St Firmware | ||
Phoenixcontact Fl Switch 3008 Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 3008 | ||
PhoenixContact FL Switch Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 3008t Firmware | ||
Phoenix Contact FL Switch 3006T-2FX SM Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 3006t-2fx Sm Firmware | ||
Phoenix Contact FL Switch 3006T-2FX ST Firmware | >=1.0<=1.32 | |
Phoenix Contact FL Switch 3006T-2FX ST Firmware | ||
Phoenixcontact FL Switch 3012e-2sfx | >=1.0<=1.32 | |
Phoenixcontact FL Switch 3012e-2sfx Firmware | ||
Phoenixcontact FL Switch 3016e Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 3016e Firmware | ||
Phoenixcontact FL Switch 3016t Firmware | >=1.0<=1.32 | |
Phoenix Contact FL Switch 3016 | ||
Phoenixcontact FL Switch 3016t Firmware | >=1.0<=1.32 | |
Phoenixcontact FL Switch 3016t Firmware | ||
Phoenix Contact FL Switch 3006T-2FX SM Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 3006t-2fx Sm Firmware | ||
Phoenixcontact Fl Switch 4008t-2sfp Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4008t-2sfp Firmware | ||
Phoenix Contact FL Switch 4008T-2GT-4FX SM Firmware | >=1.0<=1.32 | |
Phoenix Contact FL Switch 4008T-2GT-4FX SM Firmware | ||
Phoenix Contact FL Switch 4008T-2GT-3FX SM | >=1.0<=1.32 | |
Phoenix Contact FL Switch 4008T-2GT-3FX SM | ||
Phoenixcontact FL Switch 4808E-16FX LC-4GC | >=1.0<=1.32 | |
Phoenix Contact FL Switch 4808E-16FX LC-4GC Firmware | ||
Phoenixcontact FL Switch 4808E-16FX LC-4GC | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4808e-16fx Sm-4gc Firmware | ||
Phoenixcontact FL Switch 4808E-16FX SM ST-4GC | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4808e-16fx Sm-4gc Firmware | ||
Phoenixcontact FL Switch 4808E-16FX LC-4GC Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4808e-16fx St-4gc Firmware | ||
Phoenixcontact Fl Switch 4808e-16fx Sm Lc-4gc Firmware | >=1.0<=1.32 | |
Phoenix Contact FL Switch 4808E-16FX-4GC | ||
Phoenixcontact FL Switch 4808E-16FX LC-4GC Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4808e-16fx Sm Lc-4gc Firmware | ||
Phoenixcontact FL Switch 4012T 2GT 2FX | >=1.0<=1.32 | |
Phoenix Contact FL Switch 4012T-2GT-2FX ST Firmware | ||
Phoenixcontact FL Switch 4012T 2GT 2FX | >=1.0<=1.32 | |
Phoenixcontact FL Switch 4012T 2GT 2FX | ||
Phoenixcontact Fl Switch 4824e-4gc Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4824e-4gc | ||
Phoenixcontact Fl Switch 4800e-24fx Sm-4gc Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4800e-24fx Sm-4gc Firmware | ||
Phoenixcontact Fl Switch 4800e-24fx Sm-4gc | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4800e-24fx Sm-4gc Firmware | ||
Phoenixcontact Fl Switch 3012e-2fx Sm Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 3012e-2fx Sm Firmware | ||
Phoenixcontact Fl Switch 4000t-8poe-2sfp-r Firmware | >=1.0<=1.32 | |
Phoenixcontact Fl Switch 4000t-8poe-2sfp-r Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-16741 is rated as medium with a score of 5.3.
To fix CVE-2017-16741, update the firmware of the affected Phoenix Contact FL Switch devices to a version beyond 1.32.
CVE-2017-16741 affects Phoenix Contact FL Switch 3xxx, 4xxx, and 48xxx Series devices running firmware versions 1.0 to 1.32.
CVE-2017-16741 is classified as an Information Exposure vulnerability.
Yes, CVE-2017-16741 can be exploited by a remote unauthenticated attacker using Monitor Mode on the device.