HIGH · 7.4

CVE-2021-21004

In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

Vulnerability Description

In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
PhoenixcontactFl Switch Smcs 16Tx Firmware<= 4.70
PhoenixcontactFl Switch Smcs 16Tx-
PhoenixcontactFl Switch Smcs 14Tx\/2Fx Firmware<= 4.70
PhoenixcontactFl Switch Smcs 14Tx\/2Fx-
PhoenixcontactFl Switch Smcs 14Tx\/2Fx-Sm Firmware<= 4.70
PhoenixcontactFl Switch Smcs 14Tx\/2Fx-Sm-
PhoenixcontactFl Switch Smcs 8Gt Firmware<= 4.70
PhoenixcontactFl Switch Smcs 8Gt-
PhoenixcontactFl Switch Smcs 6Gt\/2Sfp Firmware<= 4.70
PhoenixcontactFl Switch Smcs 6Gt\/2Sfp-
PhoenixcontactFl Switch Smcs 8Tx-Pn Firmware<= 4.70
PhoenixcontactFl Switch Smcs 8Tx-Pn-
PhoenixcontactFl Switch Smcs 4Tx-Pn Firmware<= 4.70
PhoenixcontactFl Switch Smcs 4Tx-Pn-
PhoenixcontactFl Switch Smcs 8Tx Firmware<= 4.70
PhoenixcontactFl Switch Smcs 8Tx-
PhoenixcontactFl Switch Smcs 6Tx\/2Sfp Firmware<= 4.70
PhoenixcontactFl Switch Smcs 6Tx\/2Sfp-
PhoenixcontactFl Switch Smn 6Tx\/2Pof-Pn Firmware<= 4.70
PhoenixcontactFl Switch Smn 6Tx\/2Pof-Pn-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-21004?

CVE-2021-21004 is a vulnerability with a CVSS score of 7.4 (HIGH). In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

How severe is CVE-2021-21004?

CVE-2021-21004 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-21004?

Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Fl Switch Smcs 16Tx Firmware, Phoenixcontact Fl Switch Smcs 16Tx, Phoenixcontact Fl Switch Smcs 14Tx\/2Fx Firmware, Phoenixcontact Fl Switch Smcs 14Tx\/2Fx, Phoenixcontact Fl Switch Smcs 14Tx\/2Fx-Sm Firmware.