First published: Fri Jun 25 2021(Updated: )
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenixcontact Fl Switch Smcs 16tx Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 16tx | ||
Phoenixcontact Fl Switch Smcs 14tx\/2fx Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 14tx\/2fx | ||
Phoenixcontact Fl Switch Smcs 14tx\/2fx-sm Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 14tx\/2fx-sm | ||
Phoenixcontact Fl Switch Smcs 8gt Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 8gt | ||
Phoenixcontact Fl Switch Smcs 6gt\/2sfp Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 6gt\/2sfp | ||
Phoenixcontact Fl Switch Smcs 8tx-pn Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 8tx-pn | ||
Phoenixcontact Fl Switch Smcs 4tx-pn Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 4tx-pn | ||
Phoenixcontact Fl Switch Smcs 8tx Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 8tx | ||
Phoenixcontact Fl Switch Smcs 6tx\/2sfp Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 6tx\/2sfp | ||
Phoenixcontact Fl Switch Smn 6tx\/2pof-pn Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smn 6tx\/2pof-pn | ||
Phoenixcontact Fl Switch Smn 8tx-pn Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smn 8tx-pn | ||
Phoenixcontact Fl Switch Smn 6tx\/2fx Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smn 6tx\/2fx | ||
Phoenixcontact Fl Switch Smn 6tx\/2fx Sm Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smn 6tx\/2fx Sm | ||
Phoenixcontact Fl Nat Smn 8tx Firmware | <=4.63 | |
Phoenixcontact Fl Nat Smn 8tx | ||
Phoenixcontact Fl Nat Smn 8tx-m Firmware | <=4.63 | |
Phoenixcontact Fl Nat Smn 8tx-m |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-21005.
CVE-2021-21005 has a severity of 7.5 (High).
Phoenix Contact FL SWITCH SMCS series products in multiple versions are affected.
An attacker can crash the network stack by sending a hand-crafted TCP packet with the Urgent-Flag set and the Urgent-Pointer set to 0.
To fix CVE-2021-21005, the affected device needs to be rebooted.