First published: Fri Jun 25 2021(Updated: )
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phoenixcontact FL Switch SMCS 16TX Firmware | <=4.70 | |
Phoenix Contact FL Switch SMCS 16TX | ||
Phoenixcontact Fl Switch Smcs 14tx/2fx Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 14tx/2fx | ||
Phoenixcontact Fl Switch Smcs 14tx/2fx-sm Firmware | <=4.70 | |
Phoenix Contact FL Switch SMCS 14TX/2FX-SM | ||
Phoenix Contact FL Switch SMCS 8GT Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 8gt Firmware | ||
Phoenixcontact Fl Switch Smcs 6gt/2sfp Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 6gt/2sfp | ||
Phoenixcontact Fl Switch Smn 8tx-pn Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 8tx-pn Firmware | ||
Phoenix Contact FL Switch SMCS 4TX-PN Firmware | <=4.70 | |
Phoenix Contact FL Switch SMCS 4TX-PN Firmware | ||
Phoenixcontact Fl Switch Smcs 8tx Firmware | <=4.70 | |
Phoenix Contact FL Switch SMCS 8TX | ||
Phoenixcontact Fl Switch Smcs 6tx/2sfp Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smcs 6tx/2sfp | ||
Phoenix Contact FL Switch SMN 6TX/2POF-PN Firmware | <=4.70 | |
Phoenix Contact FL Switch SMN 6TX/2POF-PN | ||
Phoenix Contact FL Switch SMN 8TX-PN Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smn 8tx-pn Firmware | ||
Phoenixcontact Fl Switch Smn 6tx/2fx Firmware | <=4.70 | |
Phoenixcontact Fl Switch Smn 6tx/2fx | ||
Phoenixcontact Fl Switch Smn 6tx/2fx Sm Firmware | <=4.70 | |
Phoenix Contact FL Switch SMN 6TX/2FX SM | ||
Phoenix Contact FL NAT SMN 8TX Firmware | <=4.63 | |
Phoenix Contact FL NAT SMN 8TX-M | ||
Phoenix Contact FL NAT SMN 8TX-M Firmware | <=4.63 | |
Phoenix Contact FL NAT SMN 8TX-M Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-21005.
CVE-2021-21005 has a severity of 7.5 (High).
Phoenix Contact FL SWITCH SMCS series products in multiple versions are affected.
An attacker can crash the network stack by sending a hand-crafted TCP packet with the Urgent-Flag set and the Urgent-Pointer set to 0.
To fix CVE-2021-21005, the affected device needs to be rebooted.