Required CVE Record Information
Description
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://cert.vde.com/en-us/advisories/vde-2017-006 x_transferred
- https://ics-cert.us-cert.gov/advisories/ICSA-18-011-03 x_transferred