7.5
CWE
798
Advisory Published
Updated

CVE-2021-33540: Phoenix Contact: Undocumented FTP acces in certain AXL F BK and IL BK devices

First published: Wed Jun 23 2021(Updated: )

In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

Credit: info@cert.vde.com

Affected SoftwareAffected VersionHow to fix
Phoenixcontact Axl F Bk Pn Tps Xc Firmware<1.30
Phoenixcontact Axl F Bk Pn Tps Xc
Phoenixcontact Axl F Bk Pn Tps Firmware<1.30
Phoenixcontact Axl F Bk Pn Tps
Phoenixcontact Axl F Bk Eip Firmware<1.30
Phoenixcontact Axl F Bk Eip
Phoenixcontact Axl F Bk Eip Ef Firmware<1.30
Phoenixcontact Axl F Bk Eip Ef
Phoenixcontact Axl F Bk Eth Firmware<1.30
Phoenixcontact Axl F Bk Eth
Phoenixcontact Axl F Bk Eth Xc Firmware<1.30
Phoenixcontact Axl F Bk Eth Xc
Phoenixcontact Axl F Bk S35 Firmware<1.40
Phoenixcontact Axl F Bk S35
Phoenixcontact Axl F Bk Pn Firmware
Phoenixcontact Axl F Bk Pn
Phoenixcontact Axl F Bk Pn Xc Firmware
Phoenixcontact Axl F Bk Pn Xc
Phoenixcontact Axl F Bk Eth Net2 Firmware
Phoenixcontact Axl F Bk Eth Net2
Phoenixcontact Axl F Bk Sas Firmware
Phoenixcontact Axl F Bk Sas
Phoenixcontact Il Pn Bk-pac Firmware
Phoenixcontact Il Pn Bk-pac
Phoenixcontact Il Pn Bk Di8 Do4 2tx-pac Firmware
Phoenixcontact Il Pn Bk Di8 Do4 2tx-pac
Phoenixcontact Il Pn Bk Di8 Do4 2scrj-pac Firmware
Phoenixcontact Il Pn Bk Di8 Do4 2scrj-pac
Phoenixcontact Il Eth Bk Di8 Do4 2tx-xc-pac Firmware
Phoenixcontact Il Eth Bk Di8 Do4 2tx-xc-pac
Phoenixcontact Il Eth Bk Di8 Do4 2tx-pac Firmware
Phoenixcontact Il Eth Bk Di8 Do4 2tx-pac
Phoenixcontact Il Eip Bk Di8 Do4 2tx-pac Firmware
Phoenixcontact Il Eip Bk Di8 Do4 2tx-pac
Phoenixcontact Il S3 Bk Di8 Do4 2tx-pac Firmware
Phoenixcontact Il S3 Bk Di8 Do4 2tx-pac

Remedy

Please refer to the advisory (https://cert.vde.com/en-us/advisories/vde-2021-021) for a list of updated firmware versions for remediation.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2021-33540?

    CVE-2021-33540 is a vulnerability in certain devices of the Phoenix Contact AXL F BK and IL BK product families that allows undocumented password-protected FTP access to the root directory.

  • Which devices are affected by CVE-2021-33540?

    Devices of the Phoenix Contact AXL F BK and IL BK product families are affected by CVE-2021-33540.

  • What is the severity of CVE-2021-33540?

    CVE-2021-33540 has a severity rating of 7.3 (high).

  • How can I fix CVE-2021-33540?

    To fix CVE-2021-33540, it is recommended to apply the necessary patches and updates provided by Phoenix Contact.

  • Where can I find more information about CVE-2021-33540?

    You can find more information about CVE-2021-33540 on the VDE CERT advisory page: https://cert.vde.com/en-us/advisories/vde-2021-021

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203