Vulnerability Description
In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phoenixcontact | Axl F Bk Pn Tps Xc Firmware | < 1.30 |
| Phoenixcontact | Axl F Bk Pn Tps Xc | - |
| Phoenixcontact | Axl F Bk Pn Tps Firmware | < 1.30 |
| Phoenixcontact | Axl F Bk Pn Tps | - |
| Phoenixcontact | Axl F Bk Eip Firmware | < 1.30 |
| Phoenixcontact | Axl F Bk Eip | - |
| Phoenixcontact | Axl F Bk Eip Ef Firmware | < 1.30 |
| Phoenixcontact | Axl F Bk Eip Ef | - |
| Phoenixcontact | Axl F Bk Eth Firmware | < 1.30 |
| Phoenixcontact | Axl F Bk Eth | - |
| Phoenixcontact | Axl F Bk Eth Xc Firmware | < 1.30 |
| Phoenixcontact | Axl F Bk Eth Xc | - |
| Phoenixcontact | Axl F Bk S35 Firmware | < 1.40 |
| Phoenixcontact | Axl F Bk S35 | - |
| Phoenixcontact | Axl F Bk Pn Firmware | All versions |
| Phoenixcontact | Axl F Bk Pn | - |
| Phoenixcontact | Axl F Bk Pn Xc Firmware | All versions |
| Phoenixcontact | Axl F Bk Pn Xc | - |
| Phoenixcontact | Axl F Bk Eth Net2 Firmware | All versions |
| Phoenixcontact | Axl F Bk Eth Net2 | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en-us/advisories/vde-2021-021Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2021-021Third Party Advisory
FAQ
What is CVE-2021-33540?
CVE-2021-33540 is a vulnerability with a CVSS score of 7.3 (HIGH). In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.
How severe is CVE-2021-33540?
CVE-2021-33540 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33540?
Check the references section above for vendor advisories and patch information. Affected products include: Phoenixcontact Axl F Bk Pn Tps Xc Firmware, Phoenixcontact Axl F Bk Pn Tps Xc, Phoenixcontact Axl F Bk Pn Tps Firmware, Phoenixcontact Axl F Bk Pn Tps, Phoenixcontact Axl F Bk Eip Firmware.