SB2018011602 - Multiple vulnerabilities in PHOENIX CONTACT FL SWITCH
Published: January 16, 2018
Security Bulletin ID
SB2018011602
Severity
High
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Privilege escalation (CVE-ID: CVE-2017-16743)
The vulnerability allows a remote attacker to gain elevated privileges.The weakness exists due to improper authorization. A remote attacker can send a specially crafted HTTP request, bypass authentication and gain administrative privileges on the target device.
2) Information disclosure (CVE-ID: CVE-2017-16741)
The vulnerability allows a remote attacker to obtain potentially sensitive information.The weakness exists due to unspecified error. A remote attacker can use Monitor Mode on the device to read diagnostic information on the target device.
Remediation
Install update from vendor's website.